{"id":"CVE-2025-64102","aliases":["GHSA-xrw9-r35x-x878","GO-2025-4085"],"url":"https://o3.security/vulnerability/CVE-2025-64102","summary":"Zitadel allows brute-forcing authentication factors","details":"Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an online brute-force attack on OTP, TOTP, and passwords. While Zitadel allows preventing online brute force attacks in scenarios like TOTP, Email OTP, or passwords using a lockout mechanism. The mechanism is not enabled by default and can cause a denial of service for the corresponding user if enabled. Additionally, the mitigation strategies were not fully implemented in the more recent resource-based APIs. This vulnerability is fixed in 4.6.0, 3.4.3, and 2.71.18.","published":"2025-10-29T18:36:15.390Z","modified":"2026-08-12T03:51:13.530112058Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/zitadel/zitadel/v2","fixedVersion":"2.71.18"},{"ecosystem":"Go","name":"github.com/zitadel/zitadel","fixedVersion":"1.80.0-v2.20.0.20251029090735-b8db8cdf9cc8"}],"fix":{"url":"https://github.com/zitadel/zitadel/commit/b8db8cdf9cc8ea13f461758aef12457f8b7d972a","label":"zitadel/zitadel@b8db8cd"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64102.json"},{"type":"ADVISORY","url":"https://github.com/zitadel/zitadel/security/advisories/GHSA-xrw9-r35x-x878"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64102"},{"type":"FIX","url":"https://github.com/zitadel/zitadel/commit/b8db8cdf9cc8ea13f461758aef12457f8b7d972a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.530112058Z"}}