User Enumeration Vulnerability in Zitadel Identity Infrastructure Software
CVE-2025-31124
What is CVE-2025-31124?
Zitadel, an open-source identity infrastructure solution, is affected by a vulnerability that allows for user enumeration. When administrators enable the 'Ignoring unknown usernames' setting to mitigate attacks aiming at username guessing, the system still normalizes usernames. This leads to unintentional disclosure of a user's existence by allowing attackers to infer valid usernames based on the login responses. Instead of properly denying existence as intended, legitimate user prompts are shown even when credentials do not exist, indicating a flaw in the user verification process. The issue has been addressed in multiple updated versions of the software.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
zitadel >= 2.62.0, < 2.63.9 < 2.62.0, 2.63.9
zitadel >= 2.64.0-rc.1, < 2.64.6 < 2.64.0-rc.1, 2.64.6
zitadel >= 2.65.0-rc.1, < 2.65.7 < 2.65.0-rc.1, 2.65.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
