Repository navigation
Releases: HomeLabHD/zitadel
Release list
v4.19.4
📦 zitadel — v4.19.4
Release type: latest • Commit:
7776c7f
Security:
Image Availability
zitadel
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel |
v4.19.4 · latest |
| Docker Hub | docker.io/hlhd/zitadel |
v4.19.4 · latest |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel |
v4.19.4 · latest |
zitadel-login
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel-login |
v4.19.4 · latest |
| Docker Hub | docker.io/hlhd/zitadel-login |
v4.19.4 · latest |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel-login |
v4.19.4 · latest |
Digest pull commands & supply chain artifacts
docker.io/hlhd/zitadel
docker pull docker.io/hlhd/zitadel@sha256:36f5d8cb879578137d0d5dc165a3b832af31a97ea0fc83f43747577d17fa5219
docker.io/hlhd/zitadel-login
docker pull docker.io/hlhd/zitadel-login@sha256:5d6dcd3940ead2d992eabf17311d5ced77df4c0493b6f95397bcf04c4d528f74
cr.pcfae.com/hlhd/zitadel
docker pull cr.pcfae.com/hlhd/zitadel@sha256:36f5d8cb879578137d0d5dc165a3b832af31a97ea0fc83f43747577d17fa5219
cr.pcfae.com/hlhd/zitadel-login
docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:5d6dcd3940ead2d992eabf17311d5ced77df4c0493b6f95397bcf04c4d528f74
ghcr.io/homelabhd/zitadel
docker pull ghcr.io/homelabhd/zitadel@sha256:36f5d8cb879578137d0d5dc165a3b832af31a97ea0fc83f43747577d17fa5219
ghcr.io/homelabhd/zitadel-login
docker pull ghcr.io/homelabhd/zitadel-login@sha256:5d6dcd3940ead2d992eabf17311d5ced77df4c0493b6f95397bcf04c4d528f74
Highlights
- Fork of upstream v4.19.4 carrying the login-v2 project private-labeling fix (zitadel#10692): the OIDC auth request resolves the branding org server-side (org scope, else the requested project's private-labeling setting, else the instance default) and login v2 honors it for branding only — login policy, IdP discovery, and user discovery keep the instance default org.
Notable Changes
Features
- eventstore: remove application constraints by app owner (zitadel#12798) (Silvan)
- database: publish pgxpool pool stats as metrics (zitadel#12737) (Tim Möhlmann)
- telemetry: auto detect google attributes (zitadel#12694) (Tim Möhlmann)
Bug Fixes
- honor project private labeling (zitadel#10692) + self-contained builds (SoFMeRight)
- notification: correct ID order of the invite code sent handler (zitadel#12846) (Livio Spring)
- actions: set instance ID in async execution worker context (zitadel#12730) (Temuri Takalandze)
- skip finalized unique-constraint backfill and exclusive owner deletes (zitadel#12833) (Silvan)
- oidc: require admin.impersonation to impersonate administrators (Tim Möhlmann)
- login: sign session cookie entries (Max Peintner)
- idp: reject SAML assertions from a different IdP than the intent (Marco A.)
- setup step 79 batch unique constraint owner backfill (zitadel#12803) (Silvan)
- eventstore: omit owners on empty unique constraint inserts (zitadel#12785) (Silvan)
- eventstore: add owners to unique constraints (zitadel#12740) (Silvan)
- login: forward login_hint to the external IdP (zitadel#12760) (Max Peintner)
- login: verify API credentials at startup instead of in readiness probe (zitadel#12742) (Max Peintner)
- eventstore: prevent projections from skipping events (zitadel#12703) (Silvan)
- crypto: use authenticated encryption for IDP intent tokens (Livio Spring)
- security: check auth method permission on the user's organization (Marco A.)
- login: authorize IDP linking via enrollment guard, not isSessionValid (gayathri)
- login: translate authentication and OTP strings (zitadel#12668) (Matías Racedo)
Performance
- query: stop expanding login names for every ListUsers row (zitadel#12826) (Silvan)
- query: index users14 by instance and org (zitadel#12830) (Silvan)
- eventstore: order by sort key as column list instead of row constructor (zitadel#12792) (Livio Spring)
- eventstore: order events API by creation date (zitadel#12789) (Livio Spring)
- eventstore: read projection events per event type (zitadel#12753) (Tim Möhlmann)
- query: use UNION of index seeks for ListUsers login equality (zitadel#12701) (Silvan)
Documentation
- add fork note and keep-current warning to README (SoFMeRight)
- fix transparency issue on docs search modal (zitadel#12782) (Federico Coppede)
- migrate to native Fumadocs search & UI fixes (zitadel#12732) (Federico Coppede)
- fix broken links to renamed repository paths (zitadel#12618) (Livio Spring)
- error reference page fails to load, missing basePath in fetch (zitadel#12704) (Rajat Singh)
- add searchable API error reference (zitadel#12502) (Rajat Singh)
- update knowledge gap ID 66 (zitadel#12691) (zitadel-knowledge-bot[bot])
- add instance administrator hardening guide (zitadel#12678) (Livio Spring)
- perf: v4.17.1 results and harness fixes (zitadel#12651) (Tim Möhlmann)
Tests
- fix backfill test (adlerhurst)
Maintenance
- add GitLab CI, scribe assets, preset cache, and the populated fork README (SoFMeRight)
- carry StageFreight governance onto the v4.19.4 base (SoFMeRight)
- Add information for contributors about next gen (zitadel#12741) (Fabienne Bühler)
- gRPC-Go deps update to 1.83.2 (zitadel#12680) (Marco A.)
Other Changes
- Merge commit from fork (gayathri)
Security
Vulnerability details (3 high, 10 medium, 8 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2026-46600 | stdlib | go1.25.14 | 1.26.6 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. |
| High | GO-2026-6355 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global... |
| High | GO-2026-6354 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection... |
| Medium | CVE-2025-24358 | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ... |
| Medium | CVE-2025-47909 | github.com/gorilla/csrf | v1.7.2 | — | Hosts listed in TrustedOrigins implicitly allow requests from the corr ... |
| Medium | CVE-2026-81871 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration |
| Medium | CVE-2026-81872 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission |
| Medium | CVE-2026-56855 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages |
| Medium | CVE-2026-78662 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding |
| Medium | GHSA-hjf4-fphr-2h65 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full |
| Medium | GHSA-rq77-p4h8-4crw | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf CSRF vulnerability due to broken Referer validation |
| Medium | GHSA-w34q-cm8f-9c5x | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning |
| Medium | GHSA-82ff-hg59-8x73 | github.com/gorilla/csrf | v1.7.2 | — | github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| ... |
latest-dev
📦 zitadel — v4.19.4
Release type: prerelease • Commit:
7776c7f
Security:
Image Availability
zitadel
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel |
dev-7776c7f · latest-dev |
| Docker Hub | docker.io/hlhd/zitadel |
dev-7776c7f · latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel |
dev-7776c7f · latest-dev |
zitadel-login
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel-login |
dev-7776c7f · latest-dev |
| Docker Hub | docker.io/hlhd/zitadel-login |
dev-7776c7f · latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel-login |
dev-7776c7f · latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/zitadel
docker pull docker.io/hlhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7
docker.io/hlhd/zitadel-login
docker pull docker.io/hlhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21
cr.pcfae.com/hlhd/zitadel
docker pull cr.pcfae.com/hlhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7
cr.pcfae.com/hlhd/zitadel-login
docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21
ghcr.io/homelabhd/zitadel
docker pull ghcr.io/homelabhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7
ghcr.io/homelabhd/zitadel-login
docker pull ghcr.io/homelabhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21
Security
Vulnerability details (3 high, 10 medium, 8 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2026-46600 | stdlib | go1.25.14 | 1.26.6 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. |
| High | GO-2026-6355 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global... |
| High | GO-2026-6354 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection... |
| Medium | CVE-2025-24358 | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ... |
| Medium | CVE-2025-47909 | github.com/gorilla/csrf | v1.7.2 | — | Hosts listed in TrustedOrigins implicitly allow requests from the corr ... |
| Medium | CVE-2026-81871 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration |
| Medium | CVE-2026-81872 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission |
| Medium | CVE-2026-56855 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages |
| Medium | CVE-2026-78662 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding |
| Medium | GHSA-hjf4-fphr-2h65 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full |
| Medium | GHSA-rq77-p4h8-4crw | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf CSRF vulnerability due to broken Referer validation |
| Medium | GHSA-w34q-cm8f-9c5x | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning |
| Medium | GHSA-82ff-hg59-8x73 | github.com/gorilla/csrf | v1.7.2 | — | github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
Full changelog
No changes found.
dev-7776c7f
📦 zitadel — v4.19.4
Release type: prerelease • Commit:
7776c7f
Security:
Image Availability
zitadel
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel |
dev-7776c7f · latest-dev |
| Docker Hub | docker.io/hlhd/zitadel |
dev-7776c7f · latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel |
dev-7776c7f · latest-dev |
zitadel-login
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel-login |
dev-7776c7f · latest-dev |
| Docker Hub | docker.io/hlhd/zitadel-login |
dev-7776c7f · latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel-login |
dev-7776c7f · latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/zitadel
docker pull docker.io/hlhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7
docker.io/hlhd/zitadel-login
docker pull docker.io/hlhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21
cr.pcfae.com/hlhd/zitadel
docker pull cr.pcfae.com/hlhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7
cr.pcfae.com/hlhd/zitadel-login
docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21
ghcr.io/homelabhd/zitadel
docker pull ghcr.io/homelabhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7
ghcr.io/homelabhd/zitadel-login
docker pull ghcr.io/homelabhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21
Security
Vulnerability details (3 high, 10 medium, 8 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2026-46600 | stdlib | go1.25.14 | 1.26.6 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. |
| High | GO-2026-6355 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global... |
| High | GO-2026-6354 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection... |
| Medium | CVE-2025-24358 | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ... |
| Medium | CVE-2025-47909 | github.com/gorilla/csrf | v1.7.2 | — | Hosts listed in TrustedOrigins implicitly allow requests from the corr ... |
| Medium | CVE-2026-81871 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration |
| Medium | CVE-2026-81872 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission |
| Medium | CVE-2026-56855 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages |
| Medium | CVE-2026-78662 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding |
| Medium | GHSA-hjf4-fphr-2h65 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full |
| Medium | GHSA-rq77-p4h8-4crw | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf CSRF vulnerability due to broken Referer validation |
| Medium | GHSA-w34q-cm8f-9c5x | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning |
| Medium | GHSA-82ff-hg59-8x73 | github.com/gorilla/csrf | v1.7.2 | — | github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
Full changelog
No changes found.
Container Images
v4.17.3
📦 zitadel — v4.17.3
Release type: latest • Commit:
739cbc0
Security:
Image Availability
zitadel
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel |
v4.17.3 · latest |
| Docker Hub | docker.io/hlhd/zitadel |
v4.17.3 · latest |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel |
v4.17.3 · latest |
zitadel-login
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel-login |
v4.17.3 · latest |
| Docker Hub | docker.io/hlhd/zitadel-login |
v4.17.3 · latest |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel-login |
v4.17.3 · latest |
Digest pull commands & supply chain artifacts
docker.io/hlhd/zitadel
docker pull docker.io/hlhd/zitadel@sha256:8591ee57f33c924ffab2409b7ed9d76d1128ac652452839ddafba24db5387c5b
docker.io/hlhd/zitadel-login
docker pull docker.io/hlhd/zitadel-login@sha256:fd49ee3641fa9123db3316ff0f97a1d705d215094c213fd67d3c20813fcaf024
cr.pcfae.com/hlhd/zitadel
docker pull cr.pcfae.com/hlhd/zitadel@sha256:8591ee57f33c924ffab2409b7ed9d76d1128ac652452839ddafba24db5387c5b
cr.pcfae.com/hlhd/zitadel-login
docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:fd49ee3641fa9123db3316ff0f97a1d705d215094c213fd67d3c20813fcaf024
ghcr.io/homelabhd/zitadel
docker pull ghcr.io/homelabhd/zitadel@sha256:8591ee57f33c924ffab2409b7ed9d76d1128ac652452839ddafba24db5387c5b
ghcr.io/homelabhd/zitadel-login
docker pull ghcr.io/homelabhd/zitadel-login@sha256:fd49ee3641fa9123db3316ff0f97a1d705d215094c213fd67d3c20813fcaf024
Highlights
- lint: exclude internal/static/i18n from lint (upstream en.yaml duplicate key)
- login-v2: honor project private labeling (zitadel#10692) + self-contained builds [v4.17.3 base]
- crypto: use authenticated encryption for IDP intent tokens
- security: check auth method permission on the user's organization
- login: authorize IDP linking via enrollment guard, not isSessionValid
- login: translate authentication and OTP strings (zitadel#12668)
Notable Changes
Bug Fixes
- lint: exclude internal/static/i18n from lint (upstream en.yaml duplicate key) (SoFMeRight)
- login-v2: honor project private labeling (zitadel#10692) + self-contained builds [v4.17.3 base] (SoFMeRight)
- crypto: use authenticated encryption for IDP intent tokens (Livio Spring)
- security: check auth method permission on the user's organization (Marco A.)
- login: authorize IDP linking via enrollment guard, not isSessionValid (gayathri)
- login: translate authentication and OTP strings (zitadel#12668) (Matías Racedo)
Documentation
- perf: v4.17.1 results and harness fixes (zitadel#12651) (Tim Möhlmann)
Maintenance
- governance: carry SF config onto the v4.17.3 base (SoFMeRight)
- gRPC-Go deps update to 1.83.2 (zitadel#12680) (Marco A.)
Security
Vulnerability details (3 high, 10 medium, 8 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2026-46600 | stdlib | go1.25.14 | 1.26.6 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. |
| High | GO-2026-6355 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global... |
| High | GO-2026-6354 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection... |
| Medium | CVE-2025-24358 | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ... |
| Medium | CVE-2025-47909 | github.com/gorilla/csrf | v1.7.2 | — | Hosts listed in TrustedOrigins implicitly allow requests from the corr ... |
| Medium | CVE-2026-81871 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration |
| Medium | CVE-2026-81872 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission |
| Medium | CVE-2026-56855 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages |
| Medium | CVE-2026-78662 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding |
| Medium | GHSA-hjf4-fphr-2h65 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full |
| Medium | GHSA-rq77-p4h8-4crw | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf CSRF vulnerability due to broken Referer validation |
| Medium | GHSA-w34q-cm8f-9c5x | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning |
| Medium | GHSA-82ff-hg59-8x73 | github.com/gorilla/csrf | v1.7.2 | — | github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
Full changelog
- [
739cbc0] exclude internal/static/i18n from lint (upstream en.yaml duplicate key) (SoFMeRight) - [
ef7f04d] carry SF config onto the v4.17.3 base (SoFMeRight) - [
d9c4aff] honor project private labeling (zitadel#10692) + self-contained builds [v4.17.3 base] (SoFMeRight) - [
41b1114] use authenticated encryption for IDP intent tokens (Livio Spring) - [
20f0984] check auth method permission on the user's organization (Marco A.) - [
a53fbc4] authorize IDP linking via enrollment guard, not isSessionValid (gayathri) - [
739e91e] translate authentication and OTP strings (zitadel#12668) (Matías Racedo) - [
20f006d] gRPC-Go deps update to 1.83.2 (zitadel#12680) (Marco A.) - [
a7b3f69] v4.17.1 results and harness fixes (zitadel#12651) (Tim Möhlmann)
Container Images
dev-6c72250
📦 zitadel — v4.17.3-dev+6c72250
Release type: prerelease • Commit:
6c72250
Security:
Image Availability
zitadel
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel |
dev-6c72250 · latest-dev |
| Docker Hub | docker.io/hlhd/zitadel |
dev-6c72250 · latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel |
dev-6c72250 · latest-dev |
zitadel-login
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel-login |
dev-6c72250 · latest-dev |
| Docker Hub | docker.io/hlhd/zitadel-login |
dev-6c72250 · latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel-login |
dev-6c72250 · latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/zitadel
docker pull docker.io/hlhd/zitadel@sha256:2b6a2906d1f21c8b187e737b3c67aa0a8117d0e07f0baf7fb91f8b30262a736a
docker.io/hlhd/zitadel-login
docker pull docker.io/hlhd/zitadel-login@sha256:a7cf5cf5f1a6d0c6d67f1e1115b9be1aebc7dc761b6bb6a5e92013e1c23a619f
cr.pcfae.com/hlhd/zitadel
docker pull cr.pcfae.com/hlhd/zitadel@sha256:2b6a2906d1f21c8b187e737b3c67aa0a8117d0e07f0baf7fb91f8b30262a736a
cr.pcfae.com/hlhd/zitadel-login
docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:a7cf5cf5f1a6d0c6d67f1e1115b9be1aebc7dc761b6bb6a5e92013e1c23a619f
ghcr.io/homelabhd/zitadel
docker pull ghcr.io/homelabhd/zitadel@sha256:2b6a2906d1f21c8b187e737b3c67aa0a8117d0e07f0baf7fb91f8b30262a736a
ghcr.io/homelabhd/zitadel-login
docker pull ghcr.io/homelabhd/zitadel-login@sha256:a7cf5cf5f1a6d0c6d67f1e1115b9be1aebc7dc761b6bb6a5e92013e1c23a619f
Notable Changes
Documentation
- use picture element for logo so it renders one per theme (GitLab/registry safe) (SoFMeRight)
- add fork note, keep-current warning, and scribe markers to README (SoFMeRight)
- refresh generated badges (stagefreight) ×2
Security
Vulnerability details (3 high, 10 medium, 8 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2026-46600 | stdlib | go1.25.14 | 1.26.6 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. |
| High | GO-2026-6355 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global... |
| High | GO-2026-6354 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection... |
| Medium | CVE-2025-24358 | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ... |
| Medium | CVE-2025-47909 | github.com/gorilla/csrf | v1.7.2 | — | Hosts listed in TrustedOrigins implicitly allow requests from the corr ... |
| Medium | CVE-2026-81871 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration |
| Medium | CVE-2026-81872 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission |
| Medium | CVE-2026-56855 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages |
| Medium | CVE-2026-78662 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding |
| Medium | GHSA-hjf4-fphr-2h65 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full |
| Medium | GHSA-rq77-p4h8-4crw | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf CSRF vulnerability due to broken Referer validation |
| Medium | GHSA-w34q-cm8f-9c5x | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning |
| Medium | GHSA-82ff-hg59-8x73 | github.com/gorilla/csrf | v1.7.2 | — | github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
Full changelog
- [
6c72250] use picture element for logo so it renders one per theme (GitLab/registry safe) (SoFMeRight) - [
c94986b] add fork note, keep-current warning, and scribe markers to README (SoFMeRight) - [
32b2392] refresh generated badges (stagefreight) - [
d994610] refresh generated badges (stagefreight)