Skip to content

Releases: HomeLabHD/zitadel

v4.19.4

Choose a tag to compare

@SoFMeRight SoFMeRight released this 03 Oct 07:15

📦 zitadel — v4.19.4

Release type: latest • Commit: 7776c7f

Security: ⚠️ Warning — 3 high vulnerabilities detected

Image Availability

zitadel

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel v4.19.4 · latest
Docker Hub docker.io/hlhd/zitadel v4.19.4 · latest
cr.pcfae.com cr.pcfae.com/hlhd/zitadel v4.19.4 · latest

zitadel-login

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel-login v4.19.4 · latest
Docker Hub docker.io/hlhd/zitadel-login v4.19.4 · latest
cr.pcfae.com cr.pcfae.com/hlhd/zitadel-login v4.19.4 · latest
Digest pull commands & supply chain artifacts

docker.io/hlhd/zitadel

docker pull docker.io/hlhd/zitadel@sha256:36f5d8cb879578137d0d5dc165a3b832af31a97ea0fc83f43747577d17fa5219

docker.io/hlhd/zitadel-login

docker pull docker.io/hlhd/zitadel-login@sha256:5d6dcd3940ead2d992eabf17311d5ced77df4c0493b6f95397bcf04c4d528f74

cr.pcfae.com/hlhd/zitadel

docker pull cr.pcfae.com/hlhd/zitadel@sha256:36f5d8cb879578137d0d5dc165a3b832af31a97ea0fc83f43747577d17fa5219

cr.pcfae.com/hlhd/zitadel-login

docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:5d6dcd3940ead2d992eabf17311d5ced77df4c0493b6f95397bcf04c4d528f74

ghcr.io/homelabhd/zitadel

docker pull ghcr.io/homelabhd/zitadel@sha256:36f5d8cb879578137d0d5dc165a3b832af31a97ea0fc83f43747577d17fa5219

ghcr.io/homelabhd/zitadel-login

docker pull ghcr.io/homelabhd/zitadel-login@sha256:5d6dcd3940ead2d992eabf17311d5ced77df4c0493b6f95397bcf04c4d528f74

Highlights

  • Fork of upstream v4.19.4 carrying the login-v2 project private-labeling fix (zitadel#10692): the OIDC auth request resolves the branding org server-side (org scope, else the requested project's private-labeling setting, else the instance default) and login v2 honors it for branding only — login policy, IdP discovery, and user discovery keep the instance default org.

Notable Changes

Features

  • eventstore: remove application constraints by app owner (zitadel#12798) (Silvan)
  • database: publish pgxpool pool stats as metrics (zitadel#12737) (Tim Möhlmann)
  • telemetry: auto detect google attributes (zitadel#12694) (Tim Möhlmann)

Bug Fixes

  • honor project private labeling (zitadel#10692) + self-contained builds (SoFMeRight)
  • notification: correct ID order of the invite code sent handler (zitadel#12846) (Livio Spring)
  • actions: set instance ID in async execution worker context (zitadel#12730) (Temuri Takalandze)
  • skip finalized unique-constraint backfill and exclusive owner deletes (zitadel#12833) (Silvan)
  • oidc: require admin.impersonation to impersonate administrators (Tim Möhlmann)
  • login: sign session cookie entries (Max Peintner)
  • idp: reject SAML assertions from a different IdP than the intent (Marco A.)
  • setup step 79 batch unique constraint owner backfill (zitadel#12803) (Silvan)
  • eventstore: omit owners on empty unique constraint inserts (zitadel#12785) (Silvan)
  • eventstore: add owners to unique constraints (zitadel#12740) (Silvan)
  • login: forward login_hint to the external IdP (zitadel#12760) (Max Peintner)
  • login: verify API credentials at startup instead of in readiness probe (zitadel#12742) (Max Peintner)
  • eventstore: prevent projections from skipping events (zitadel#12703) (Silvan)
  • crypto: use authenticated encryption for IDP intent tokens (Livio Spring)
  • security: check auth method permission on the user's organization (Marco A.)
  • login: authorize IDP linking via enrollment guard, not isSessionValid (gayathri)
  • login: translate authentication and OTP strings (zitadel#12668) (Matías Racedo)

Performance

  • query: stop expanding login names for every ListUsers row (zitadel#12826) (Silvan)
  • query: index users14 by instance and org (zitadel#12830) (Silvan)
  • eventstore: order by sort key as column list instead of row constructor (zitadel#12792) (Livio Spring)
  • eventstore: order events API by creation date (zitadel#12789) (Livio Spring)
  • eventstore: read projection events per event type (zitadel#12753) (Tim Möhlmann)
  • query: use UNION of index seeks for ListUsers login equality (zitadel#12701) (Silvan)

Documentation

  • add fork note and keep-current warning to README (SoFMeRight)
  • fix transparency issue on docs search modal (zitadel#12782) (Federico Coppede)
  • migrate to native Fumadocs search & UI fixes (zitadel#12732) (Federico Coppede)
  • fix broken links to renamed repository paths (zitadel#12618) (Livio Spring)
  • error reference page fails to load, missing basePath in fetch (zitadel#12704) (Rajat Singh)
  • add searchable API error reference (zitadel#12502) (Rajat Singh)
  • update knowledge gap ID 66 (zitadel#12691) (zitadel-knowledge-bot[bot])
  • add instance administrator hardening guide (zitadel#12678) (Livio Spring)
  • perf: v4.17.1 results and harness fixes (zitadel#12651) (Tim Möhlmann)

Tests

  • fix backfill test (adlerhurst)

Maintenance

  • add GitLab CI, scribe assets, preset cache, and the populated fork README (SoFMeRight)
  • carry StageFreight governance onto the v4.19.4 base (SoFMeRight)
  • Add information for contributors about next gen (zitadel#12741) (Fabienne Bühler)
  • gRPC-Go deps update to 1.83.2 (zitadel#12680) (Marco A.)

Other Changes

  • Merge commit from fork (gayathri)

Security

⚠️ Warning — 3 high vulnerabilities detected

Vulnerability details (3 high, 10 medium, 8 low)
Severity CVE Package Installed Fixed Description
High CVE-2026-46600 stdlib go1.25.14 1.26.6 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
High GO-2026-6355 golang.org/x/crypto v0.55.0 0.56.0 Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global...
High GO-2026-6354 golang.org/x/crypto v0.55.0 0.56.0 Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection...
Medium CVE-2025-24358 github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ...
Medium CVE-2025-47909 github.com/gorilla/csrf v1.7.2 — Hosts listed in TrustedOrigins implicitly allow requests from the corr ...
Medium CVE-2026-81871 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration
Medium CVE-2026-81872 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission
Medium CVE-2026-56855 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages
Medium CVE-2026-78662 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding
Medium GHSA-hjf4-fphr-2h65 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
Medium GHSA-rq77-p4h8-4crw github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf CSRF vulnerability due to broken Referer validation
Medium GHSA-w34q-cm8f-9c5x go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
Medium GHSA-82ff-hg59-8x73 github.com/gorilla/csrf v1.7.2 — github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/sdk v1.44.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
...
Read more

latest-dev

latest-dev Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 03 Oct 06:33

📦 zitadel — v4.19.4

Release type: prerelease • Commit: 7776c7f

Security: ⚠️ Warning — 3 high vulnerabilities detected

Image Availability

zitadel

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel dev-7776c7f · latest-dev
Docker Hub docker.io/hlhd/zitadel dev-7776c7f · latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/zitadel dev-7776c7f · latest-dev

zitadel-login

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel-login dev-7776c7f · latest-dev
Docker Hub docker.io/hlhd/zitadel-login dev-7776c7f · latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/zitadel-login dev-7776c7f · latest-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/zitadel

docker pull docker.io/hlhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7

docker.io/hlhd/zitadel-login

docker pull docker.io/hlhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21

cr.pcfae.com/hlhd/zitadel

docker pull cr.pcfae.com/hlhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7

cr.pcfae.com/hlhd/zitadel-login

docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21

ghcr.io/homelabhd/zitadel

docker pull ghcr.io/homelabhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7

ghcr.io/homelabhd/zitadel-login

docker pull ghcr.io/homelabhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21

Security

⚠️ Warning — 3 high vulnerabilities detected

Vulnerability details (3 high, 10 medium, 8 low)
Severity CVE Package Installed Fixed Description
High CVE-2026-46600 stdlib go1.25.14 1.26.6 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
High GO-2026-6355 golang.org/x/crypto v0.55.0 0.56.0 Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global...
High GO-2026-6354 golang.org/x/crypto v0.55.0 0.56.0 Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection...
Medium CVE-2025-24358 github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ...
Medium CVE-2025-47909 github.com/gorilla/csrf v1.7.2 — Hosts listed in TrustedOrigins implicitly allow requests from the corr ...
Medium CVE-2026-81871 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration
Medium CVE-2026-81872 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission
Medium CVE-2026-56855 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages
Medium CVE-2026-78662 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding
Medium GHSA-hjf4-fphr-2h65 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
Medium GHSA-rq77-p4h8-4crw github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf CSRF vulnerability due to broken Referer validation
Medium GHSA-w34q-cm8f-9c5x go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
Medium GHSA-82ff-hg59-8x73 github.com/gorilla/csrf v1.7.2 — github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/sdk v1.44.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/sdk v1.44.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
---
Full changelog

No changes found.

dev-7776c7f

dev-7776c7f Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 03 Oct 06:33

📦 zitadel — v4.19.4

Release type: prerelease • Commit: 7776c7f

Security: ⚠️ Warning — 3 high vulnerabilities detected

Image Availability

zitadel

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel dev-7776c7f · latest-dev
Docker Hub docker.io/hlhd/zitadel dev-7776c7f · latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/zitadel dev-7776c7f · latest-dev

zitadel-login

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel-login dev-7776c7f · latest-dev
Docker Hub docker.io/hlhd/zitadel-login dev-7776c7f · latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/zitadel-login dev-7776c7f · latest-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/zitadel

docker pull docker.io/hlhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7

docker.io/hlhd/zitadel-login

docker pull docker.io/hlhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21

cr.pcfae.com/hlhd/zitadel

docker pull cr.pcfae.com/hlhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7

cr.pcfae.com/hlhd/zitadel-login

docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21

ghcr.io/homelabhd/zitadel

docker pull ghcr.io/homelabhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7

ghcr.io/homelabhd/zitadel-login

docker pull ghcr.io/homelabhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21

Security

⚠️ Warning — 3 high vulnerabilities detected

Vulnerability details (3 high, 10 medium, 8 low)
Severity CVE Package Installed Fixed Description
High CVE-2026-46600 stdlib go1.25.14 1.26.6 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
High GO-2026-6355 golang.org/x/crypto v0.55.0 0.56.0 Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global...
High GO-2026-6354 golang.org/x/crypto v0.55.0 0.56.0 Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection...
Medium CVE-2025-24358 github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ...
Medium CVE-2025-47909 github.com/gorilla/csrf v1.7.2 — Hosts listed in TrustedOrigins implicitly allow requests from the corr ...
Medium CVE-2026-81871 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration
Medium CVE-2026-81872 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission
Medium CVE-2026-56855 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages
Medium CVE-2026-78662 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding
Medium GHSA-hjf4-fphr-2h65 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
Medium GHSA-rq77-p4h8-4crw github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf CSRF vulnerability due to broken Referer validation
Medium GHSA-w34q-cm8f-9c5x go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
Medium GHSA-82ff-hg59-8x73 github.com/gorilla/csrf v1.7.2 — github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/sdk v1.44.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/sdk v1.44.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
---
Full changelog

No changes found.

Container Images

v4.17.3

Choose a tag to compare

@SoFMeRight SoFMeRight released this 02 Oct 14:47

📦 zitadel — v4.17.3

Release type: latest • Commit: 739cbc0

Security: ⚠️ Warning — 3 high vulnerabilities detected

Image Availability

zitadel

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel v4.17.3 · latest
Docker Hub docker.io/hlhd/zitadel v4.17.3 · latest
cr.pcfae.com cr.pcfae.com/hlhd/zitadel v4.17.3 · latest

zitadel-login

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel-login v4.17.3 · latest
Docker Hub docker.io/hlhd/zitadel-login v4.17.3 · latest
cr.pcfae.com cr.pcfae.com/hlhd/zitadel-login v4.17.3 · latest
Digest pull commands & supply chain artifacts

docker.io/hlhd/zitadel

docker pull docker.io/hlhd/zitadel@sha256:8591ee57f33c924ffab2409b7ed9d76d1128ac652452839ddafba24db5387c5b

docker.io/hlhd/zitadel-login

docker pull docker.io/hlhd/zitadel-login@sha256:fd49ee3641fa9123db3316ff0f97a1d705d215094c213fd67d3c20813fcaf024

cr.pcfae.com/hlhd/zitadel

docker pull cr.pcfae.com/hlhd/zitadel@sha256:8591ee57f33c924ffab2409b7ed9d76d1128ac652452839ddafba24db5387c5b

cr.pcfae.com/hlhd/zitadel-login

docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:fd49ee3641fa9123db3316ff0f97a1d705d215094c213fd67d3c20813fcaf024

ghcr.io/homelabhd/zitadel

docker pull ghcr.io/homelabhd/zitadel@sha256:8591ee57f33c924ffab2409b7ed9d76d1128ac652452839ddafba24db5387c5b

ghcr.io/homelabhd/zitadel-login

docker pull ghcr.io/homelabhd/zitadel-login@sha256:fd49ee3641fa9123db3316ff0f97a1d705d215094c213fd67d3c20813fcaf024

Highlights

  • lint: exclude internal/static/i18n from lint (upstream en.yaml duplicate key)
  • login-v2: honor project private labeling (zitadel#10692) + self-contained builds [v4.17.3 base]
  • crypto: use authenticated encryption for IDP intent tokens
  • security: check auth method permission on the user's organization
  • login: authorize IDP linking via enrollment guard, not isSessionValid
  • login: translate authentication and OTP strings (zitadel#12668)

Notable Changes

Bug Fixes

  • lint: exclude internal/static/i18n from lint (upstream en.yaml duplicate key) (SoFMeRight)
  • login-v2: honor project private labeling (zitadel#10692) + self-contained builds [v4.17.3 base] (SoFMeRight)
  • crypto: use authenticated encryption for IDP intent tokens (Livio Spring)
  • security: check auth method permission on the user's organization (Marco A.)
  • login: authorize IDP linking via enrollment guard, not isSessionValid (gayathri)
  • login: translate authentication and OTP strings (zitadel#12668) (Matías Racedo)

Documentation

  • perf: v4.17.1 results and harness fixes (zitadel#12651) (Tim Möhlmann)

Maintenance

  • governance: carry SF config onto the v4.17.3 base (SoFMeRight)
  • gRPC-Go deps update to 1.83.2 (zitadel#12680) (Marco A.)

Security

⚠️ Warning — 3 high vulnerabilities detected

Vulnerability details (3 high, 10 medium, 8 low)
Severity CVE Package Installed Fixed Description
High CVE-2026-46600 stdlib go1.25.14 1.26.6 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
High GO-2026-6355 golang.org/x/crypto v0.55.0 0.56.0 Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global...
High GO-2026-6354 golang.org/x/crypto v0.55.0 0.56.0 Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection...
Medium CVE-2025-24358 github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ...
Medium CVE-2025-47909 github.com/gorilla/csrf v1.7.2 — Hosts listed in TrustedOrigins implicitly allow requests from the corr ...
Medium CVE-2026-81871 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration
Medium CVE-2026-81872 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission
Medium CVE-2026-56855 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages
Medium CVE-2026-78662 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding
Medium GHSA-hjf4-fphr-2h65 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
Medium GHSA-rq77-p4h8-4crw github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf CSRF vulnerability due to broken Referer validation
Medium GHSA-w34q-cm8f-9c5x go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
Medium GHSA-82ff-hg59-8x73 github.com/gorilla/csrf v1.7.2 — github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/sdk v1.44.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/sdk v1.44.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
---
Full changelog
  • [739cbc0] exclude internal/static/i18n from lint (upstream en.yaml duplicate key) (SoFMeRight)
  • [ef7f04d] carry SF config onto the v4.17.3 base (SoFMeRight)
  • [d9c4aff] honor project private labeling (zitadel#10692) + self-contained builds [v4.17.3 base] (SoFMeRight)
  • [41b1114] use authenticated encryption for IDP intent tokens (Livio Spring)
  • [20f0984] check auth method permission on the user's organization (Marco A.)
  • [a53fbc4] authorize IDP linking via enrollment guard, not isSessionValid (gayathri)
  • [739e91e] translate authentication and OTP strings (zitadel#12668) (Matías Racedo)
  • [20f006d] gRPC-Go deps update to 1.83.2 (zitadel#12680) (Marco A.)
  • [a7b3f69] v4.17.1 results and harness fixes (zitadel#12651) (Tim Möhlmann)

Container Images

dev-6c72250

dev-6c72250 Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 02 Oct 16:21

📦 zitadel — v4.17.3-dev+6c72250

Release type: prerelease • Commit: 6c72250

Security: ⚠️ Warning — 3 high vulnerabilities detected

Image Availability

zitadel

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel dev-6c72250 · latest-dev
Docker Hub docker.io/hlhd/zitadel dev-6c72250 · latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/zitadel dev-6c72250 · latest-dev

zitadel-login

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel-login dev-6c72250 · latest-dev
Docker Hub docker.io/hlhd/zitadel-login dev-6c72250 · latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/zitadel-login dev-6c72250 · latest-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/zitadel

docker pull docker.io/hlhd/zitadel@sha256:2b6a2906d1f21c8b187e737b3c67aa0a8117d0e07f0baf7fb91f8b30262a736a

docker.io/hlhd/zitadel-login

docker pull docker.io/hlhd/zitadel-login@sha256:a7cf5cf5f1a6d0c6d67f1e1115b9be1aebc7dc761b6bb6a5e92013e1c23a619f

cr.pcfae.com/hlhd/zitadel

docker pull cr.pcfae.com/hlhd/zitadel@sha256:2b6a2906d1f21c8b187e737b3c67aa0a8117d0e07f0baf7fb91f8b30262a736a

cr.pcfae.com/hlhd/zitadel-login

docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:a7cf5cf5f1a6d0c6d67f1e1115b9be1aebc7dc761b6bb6a5e92013e1c23a619f

ghcr.io/homelabhd/zitadel

docker pull ghcr.io/homelabhd/zitadel@sha256:2b6a2906d1f21c8b187e737b3c67aa0a8117d0e07f0baf7fb91f8b30262a736a

ghcr.io/homelabhd/zitadel-login

docker pull ghcr.io/homelabhd/zitadel-login@sha256:a7cf5cf5f1a6d0c6d67f1e1115b9be1aebc7dc761b6bb6a5e92013e1c23a619f

Notable Changes

Documentation

  • use picture element for logo so it renders one per theme (GitLab/registry safe) (SoFMeRight)
  • add fork note, keep-current warning, and scribe markers to README (SoFMeRight)
  • refresh generated badges (stagefreight) ×2

Security

⚠️ Warning — 3 high vulnerabilities detected

Vulnerability details (3 high, 10 medium, 8 low)
Severity CVE Package Installed Fixed Description
High CVE-2026-46600 stdlib go1.25.14 1.26.6 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
High GO-2026-6355 golang.org/x/crypto v0.55.0 0.56.0 Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global...
High GO-2026-6354 golang.org/x/crypto v0.55.0 0.56.0 Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection...
Medium CVE-2025-24358 github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ...
Medium CVE-2025-47909 github.com/gorilla/csrf v1.7.2 — Hosts listed in TrustedOrigins implicitly allow requests from the corr ...
Medium CVE-2026-81871 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration
Medium CVE-2026-81872 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission
Medium CVE-2026-56855 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages
Medium CVE-2026-78662 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding
Medium GHSA-hjf4-fphr-2h65 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
Medium GHSA-rq77-p4h8-4crw github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf CSRF vulnerability due to broken Referer validation
Medium GHSA-w34q-cm8f-9c5x go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
Medium GHSA-82ff-hg59-8x73 github.com/gorilla/csrf v1.7.2 — github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/sdk v1.44.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/sdk v1.44.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
---
Full changelog
  • [6c72250] use picture element for logo so it renders one per theme (GitLab/registry safe) (SoFMeRight)
  • [c94986b] add fork note, keep-current warning, and scribe markers to README (SoFMeRight)
  • [32b2392] refresh generated badges (stagefreight)
  • [d994610] refresh generated badges (stagefreight)

Container Images