Repository navigation
dev-7776c7f
Pre-release
Pre-release
📦 zitadel — v4.19.4
Release type: prerelease • Commit:
7776c7f
Security:
Image Availability
zitadel
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel |
dev-7776c7f · latest-dev |
| Docker Hub | docker.io/hlhd/zitadel |
dev-7776c7f · latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel |
dev-7776c7f · latest-dev |
zitadel-login
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel-login |
dev-7776c7f · latest-dev |
| Docker Hub | docker.io/hlhd/zitadel-login |
dev-7776c7f · latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel-login |
dev-7776c7f · latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/zitadel
docker pull docker.io/hlhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7
docker.io/hlhd/zitadel-login
docker pull docker.io/hlhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21
cr.pcfae.com/hlhd/zitadel
docker pull cr.pcfae.com/hlhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7
cr.pcfae.com/hlhd/zitadel-login
docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21
ghcr.io/homelabhd/zitadel
docker pull ghcr.io/homelabhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7
ghcr.io/homelabhd/zitadel-login
docker pull ghcr.io/homelabhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21
Security
Vulnerability details (3 high, 10 medium, 8 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2026-46600 | stdlib | go1.25.14 | 1.26.6 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. |
| High | GO-2026-6355 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global... |
| High | GO-2026-6354 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection... |
| Medium | CVE-2025-24358 | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ... |
| Medium | CVE-2025-47909 | github.com/gorilla/csrf | v1.7.2 | — | Hosts listed in TrustedOrigins implicitly allow requests from the corr ... |
| Medium | CVE-2026-81871 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration |
| Medium | CVE-2026-81872 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission |
| Medium | CVE-2026-56855 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages |
| Medium | CVE-2026-78662 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding |
| Medium | GHSA-hjf4-fphr-2h65 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full |
| Medium | GHSA-rq77-p4h8-4crw | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf CSRF vulnerability due to broken Referer validation |
| Medium | GHSA-w34q-cm8f-9c5x | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning |
| Medium | GHSA-82ff-hg59-8x73 | github.com/gorilla/csrf | v1.7.2 | — | github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
Full changelog
No changes found.