Repository navigation
dev-6c72250
Pre-release
Pre-release
📦 zitadel — v4.17.3-dev+6c72250
Release type: prerelease • Commit:
6c72250
Security:
Image Availability
zitadel
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel |
dev-6c72250 · latest-dev |
| Docker Hub | docker.io/hlhd/zitadel |
dev-6c72250 · latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel |
dev-6c72250 · latest-dev |
zitadel-login
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel-login |
dev-6c72250 · latest-dev |
| Docker Hub | docker.io/hlhd/zitadel-login |
dev-6c72250 · latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel-login |
dev-6c72250 · latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/zitadel
docker pull docker.io/hlhd/zitadel@sha256:2b6a2906d1f21c8b187e737b3c67aa0a8117d0e07f0baf7fb91f8b30262a736a
docker.io/hlhd/zitadel-login
docker pull docker.io/hlhd/zitadel-login@sha256:a7cf5cf5f1a6d0c6d67f1e1115b9be1aebc7dc761b6bb6a5e92013e1c23a619f
cr.pcfae.com/hlhd/zitadel
docker pull cr.pcfae.com/hlhd/zitadel@sha256:2b6a2906d1f21c8b187e737b3c67aa0a8117d0e07f0baf7fb91f8b30262a736a
cr.pcfae.com/hlhd/zitadel-login
docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:a7cf5cf5f1a6d0c6d67f1e1115b9be1aebc7dc761b6bb6a5e92013e1c23a619f
ghcr.io/homelabhd/zitadel
docker pull ghcr.io/homelabhd/zitadel@sha256:2b6a2906d1f21c8b187e737b3c67aa0a8117d0e07f0baf7fb91f8b30262a736a
ghcr.io/homelabhd/zitadel-login
docker pull ghcr.io/homelabhd/zitadel-login@sha256:a7cf5cf5f1a6d0c6d67f1e1115b9be1aebc7dc761b6bb6a5e92013e1c23a619f
Notable Changes
Documentation
- use picture element for logo so it renders one per theme (GitLab/registry safe) (SoFMeRight)
- add fork note, keep-current warning, and scribe markers to README (SoFMeRight)
- refresh generated badges (stagefreight) ×2
Security
Vulnerability details (3 high, 10 medium, 8 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2026-46600 | stdlib | go1.25.14 | 1.26.6 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. |
| High | GO-2026-6355 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global... |
| High | GO-2026-6354 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection... |
| Medium | CVE-2025-24358 | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ... |
| Medium | CVE-2025-47909 | github.com/gorilla/csrf | v1.7.2 | — | Hosts listed in TrustedOrigins implicitly allow requests from the corr ... |
| Medium | CVE-2026-81871 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration |
| Medium | CVE-2026-81872 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission |
| Medium | CVE-2026-56855 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages |
| Medium | CVE-2026-78662 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding |
| Medium | GHSA-hjf4-fphr-2h65 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full |
| Medium | GHSA-rq77-p4h8-4crw | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf CSRF vulnerability due to broken Referer validation |
| Medium | GHSA-w34q-cm8f-9c5x | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning |
| Medium | GHSA-82ff-hg59-8x73 | github.com/gorilla/csrf | v1.7.2 | — | github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
Full changelog
- [
6c72250] use picture element for logo so it renders one per theme (GitLab/registry safe) (SoFMeRight) - [
c94986b] add fork note, keep-current warning, and scribe markers to README (SoFMeRight) - [
32b2392] refresh generated badges (stagefreight) - [
d994610] refresh generated badges (stagefreight)