Skip to content

dev-7776c7f

Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 03 Oct 06:33
· 2 commits to main since this release

📦 zitadel — v4.19.4

Release type: prerelease • Commit: 7776c7f

Security: ⚠️ Warning — 3 high vulnerabilities detected

Image Availability

zitadel

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel dev-7776c7f · latest-dev
Docker Hub docker.io/hlhd/zitadel dev-7776c7f · latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/zitadel dev-7776c7f · latest-dev

zitadel-login

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel-login dev-7776c7f · latest-dev
Docker Hub docker.io/hlhd/zitadel-login dev-7776c7f · latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/zitadel-login dev-7776c7f · latest-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/zitadel

docker pull docker.io/hlhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7

docker.io/hlhd/zitadel-login

docker pull docker.io/hlhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21

cr.pcfae.com/hlhd/zitadel

docker pull cr.pcfae.com/hlhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7

cr.pcfae.com/hlhd/zitadel-login

docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21

ghcr.io/homelabhd/zitadel

docker pull ghcr.io/homelabhd/zitadel@sha256:985726a1ffa386cc18c289e54b7a8f2baa8041622df26b27a20b7b32816c4bc7

ghcr.io/homelabhd/zitadel-login

docker pull ghcr.io/homelabhd/zitadel-login@sha256:3e4c8772c862ab64d2fa0a03f0cfebeb54889ec50803ce0008382a00265dae21

Security

⚠️ Warning — 3 high vulnerabilities detected

Vulnerability details (3 high, 10 medium, 8 low)
Severity CVE Package Installed Fixed Description
High CVE-2026-46600 stdlib go1.25.14 1.26.6 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
High GO-2026-6355 golang.org/x/crypto v0.55.0 0.56.0 Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global...
High GO-2026-6354 golang.org/x/crypto v0.55.0 0.56.0 Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection...
Medium CVE-2025-24358 github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ...
Medium CVE-2025-47909 github.com/gorilla/csrf v1.7.2 — Hosts listed in TrustedOrigins implicitly allow requests from the corr ...
Medium CVE-2026-81871 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration
Medium CVE-2026-81872 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission
Medium CVE-2026-56855 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages
Medium CVE-2026-78662 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding
Medium GHSA-hjf4-fphr-2h65 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
Medium GHSA-rq77-p4h8-4crw github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf CSRF vulnerability due to broken Referer validation
Medium GHSA-w34q-cm8f-9c5x go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
Medium GHSA-82ff-hg59-8x73 github.com/gorilla/csrf v1.7.2 — github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/sdk v1.44.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/sdk v1.44.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
---
Full changelog

No changes found.

Container Images