Skip to content

v4.19.4

Latest

Choose a tag to compare

@SoFMeRight SoFMeRight released this 03 Oct 07:15

📦 zitadel — v4.19.4

Release type: latest • Commit: 7776c7f

Security: ⚠️ Warning — 3 high vulnerabilities detected

Image Availability

zitadel

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel v4.19.4 · latest
Docker Hub docker.io/hlhd/zitadel v4.19.4 · latest
cr.pcfae.com cr.pcfae.com/hlhd/zitadel v4.19.4 · latest

zitadel-login

Registry Reference Tags
GitHub Container Registry ghcr.io/homelabhd/zitadel-login v4.19.4 · latest
Docker Hub docker.io/hlhd/zitadel-login v4.19.4 · latest
cr.pcfae.com cr.pcfae.com/hlhd/zitadel-login v4.19.4 · latest
Digest pull commands & supply chain artifacts

docker.io/hlhd/zitadel

docker pull docker.io/hlhd/zitadel@sha256:36f5d8cb879578137d0d5dc165a3b832af31a97ea0fc83f43747577d17fa5219

docker.io/hlhd/zitadel-login

docker pull docker.io/hlhd/zitadel-login@sha256:5d6dcd3940ead2d992eabf17311d5ced77df4c0493b6f95397bcf04c4d528f74

cr.pcfae.com/hlhd/zitadel

docker pull cr.pcfae.com/hlhd/zitadel@sha256:36f5d8cb879578137d0d5dc165a3b832af31a97ea0fc83f43747577d17fa5219

cr.pcfae.com/hlhd/zitadel-login

docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:5d6dcd3940ead2d992eabf17311d5ced77df4c0493b6f95397bcf04c4d528f74

ghcr.io/homelabhd/zitadel

docker pull ghcr.io/homelabhd/zitadel@sha256:36f5d8cb879578137d0d5dc165a3b832af31a97ea0fc83f43747577d17fa5219

ghcr.io/homelabhd/zitadel-login

docker pull ghcr.io/homelabhd/zitadel-login@sha256:5d6dcd3940ead2d992eabf17311d5ced77df4c0493b6f95397bcf04c4d528f74

Highlights

  • Fork of upstream v4.19.4 carrying the login-v2 project private-labeling fix (zitadel#10692): the OIDC auth request resolves the branding org server-side (org scope, else the requested project's private-labeling setting, else the instance default) and login v2 honors it for branding only — login policy, IdP discovery, and user discovery keep the instance default org.

Notable Changes

Features

  • eventstore: remove application constraints by app owner (zitadel#12798) (Silvan)
  • database: publish pgxpool pool stats as metrics (zitadel#12737) (Tim Möhlmann)
  • telemetry: auto detect google attributes (zitadel#12694) (Tim Möhlmann)

Bug Fixes

  • honor project private labeling (zitadel#10692) + self-contained builds (SoFMeRight)
  • notification: correct ID order of the invite code sent handler (zitadel#12846) (Livio Spring)
  • actions: set instance ID in async execution worker context (zitadel#12730) (Temuri Takalandze)
  • skip finalized unique-constraint backfill and exclusive owner deletes (zitadel#12833) (Silvan)
  • oidc: require admin.impersonation to impersonate administrators (Tim Möhlmann)
  • login: sign session cookie entries (Max Peintner)
  • idp: reject SAML assertions from a different IdP than the intent (Marco A.)
  • setup step 79 batch unique constraint owner backfill (zitadel#12803) (Silvan)
  • eventstore: omit owners on empty unique constraint inserts (zitadel#12785) (Silvan)
  • eventstore: add owners to unique constraints (zitadel#12740) (Silvan)
  • login: forward login_hint to the external IdP (zitadel#12760) (Max Peintner)
  • login: verify API credentials at startup instead of in readiness probe (zitadel#12742) (Max Peintner)
  • eventstore: prevent projections from skipping events (zitadel#12703) (Silvan)
  • crypto: use authenticated encryption for IDP intent tokens (Livio Spring)
  • security: check auth method permission on the user's organization (Marco A.)
  • login: authorize IDP linking via enrollment guard, not isSessionValid (gayathri)
  • login: translate authentication and OTP strings (zitadel#12668) (Matías Racedo)

Performance

  • query: stop expanding login names for every ListUsers row (zitadel#12826) (Silvan)
  • query: index users14 by instance and org (zitadel#12830) (Silvan)
  • eventstore: order by sort key as column list instead of row constructor (zitadel#12792) (Livio Spring)
  • eventstore: order events API by creation date (zitadel#12789) (Livio Spring)
  • eventstore: read projection events per event type (zitadel#12753) (Tim Möhlmann)
  • query: use UNION of index seeks for ListUsers login equality (zitadel#12701) (Silvan)

Documentation

  • add fork note and keep-current warning to README (SoFMeRight)
  • fix transparency issue on docs search modal (zitadel#12782) (Federico Coppede)
  • migrate to native Fumadocs search & UI fixes (zitadel#12732) (Federico Coppede)
  • fix broken links to renamed repository paths (zitadel#12618) (Livio Spring)
  • error reference page fails to load, missing basePath in fetch (zitadel#12704) (Rajat Singh)
  • add searchable API error reference (zitadel#12502) (Rajat Singh)
  • update knowledge gap ID 66 (zitadel#12691) (zitadel-knowledge-bot[bot])
  • add instance administrator hardening guide (zitadel#12678) (Livio Spring)
  • perf: v4.17.1 results and harness fixes (zitadel#12651) (Tim Möhlmann)

Tests

  • fix backfill test (adlerhurst)

Maintenance

  • add GitLab CI, scribe assets, preset cache, and the populated fork README (SoFMeRight)
  • carry StageFreight governance onto the v4.19.4 base (SoFMeRight)
  • Add information for contributors about next gen (zitadel#12741) (Fabienne Bühler)
  • gRPC-Go deps update to 1.83.2 (zitadel#12680) (Marco A.)

Other Changes

  • Merge commit from fork (gayathri)

Security

⚠️ Warning — 3 high vulnerabilities detected

Vulnerability details (3 high, 10 medium, 8 low)
Severity CVE Package Installed Fixed Description
High CVE-2026-46600 stdlib go1.25.14 1.26.6 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
High GO-2026-6355 golang.org/x/crypto v0.55.0 0.56.0 Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global...
High GO-2026-6354 golang.org/x/crypto v0.55.0 0.56.0 Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection...
Medium CVE-2025-24358 github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ...
Medium CVE-2025-47909 github.com/gorilla/csrf v1.7.2 — Hosts listed in TrustedOrigins implicitly allow requests from the corr ...
Medium CVE-2026-81871 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration
Medium CVE-2026-81872 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission
Medium CVE-2026-56855 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages
Medium CVE-2026-78662 golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding
Medium GHSA-hjf4-fphr-2h65 go.opentelemetry.io/otel/sdk/log v0.19.0 0.21.0 OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
Medium GHSA-rq77-p4h8-4crw github.com/gorilla/csrf v1.7.2 1.7.3 gorilla/csrf CSRF vulnerability due to broken Referer validation
Medium GHSA-w34q-cm8f-9c5x go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 0.21.0 OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
Medium GHSA-82ff-hg59-8x73 github.com/gorilla/csrf v1.7.2 — github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low CVE-2026-81870 go.opentelemetry.io/otel/sdk v1.44.0 1.45.0 github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Low GHSA-8wmf-6v46-5gfg go.opentelemetry.io/otel/sdk v1.44.0 1.45.0 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
---
Full changelog
  • [7776c7f] add GitLab CI, scribe assets, preset cache, and the populated fork README (SoFMeRight)
  • [e3216b1] add fork note and keep-current warning to README (SoFMeRight)
  • [15d67dc] carry StageFreight governance onto the v4.19.4 base (SoFMeRight)
  • [411b264] honor project private labeling (zitadel#10692) + self-contained builds (SoFMeRight)
  • [101343a] correct ID order of the invite code sent handler (zitadel#12846) (Livio Spring)
  • [03a2469] set instance ID in async execution worker context (zitadel#12730) (Temuri Takalandze)
  • [aee8b88] skip finalized unique-constraint backfill and exclusive owner deletes (zitadel#12833) (Silvan)
  • [2c6acd8] stop expanding login names for every ListUsers row (zitadel#12826) (Silvan)
  • [d378dea] index users14 by instance and org (zitadel#12830) (Silvan)
  • [2c37c41] require admin.impersonation to impersonate administrators (Tim Möhlmann)
  • [6e4a3d4] sign session cookie entries (Max Peintner)
  • [450c056] reject SAML assertions from a different IdP than the intent (Marco A.)
  • [eb79d94] Add information for contributors about next gen (zitadel#12741) (Fabienne Bühler)
  • [f1891b8] order by sort key as column list instead of row constructor (zitadel#12792) (Livio Spring)
  • [76cd246] order events API by creation date (zitadel#12789) (Livio Spring)
  • [3a1b76e] read projection events per event type (zitadel#12753) (Tim Möhlmann)
  • [57a425f] fix transparency issue on docs search modal (zitadel#12782) (Federico Coppede)
  • [e8cdc7d] migrate to native Fumadocs search & UI fixes (zitadel#12732) (Federico Coppede)
  • [2903009] fix broken links to renamed repository paths (zitadel#12618) (Livio Spring)
  • [bd8b798] error reference page fails to load, missing basePath in fetch (zitadel#12704) (Rajat Singh)
  • [556026a] add searchable API error reference (zitadel#12502) (Rajat Singh)
  • [8319f12] update knowledge gap ID 66 (zitadel#12691) (zitadel-knowledge-bot[bot])
  • [7695976] fix backfill test (adlerhurst)
  • [42cdd5d] setup step 79 batch unique constraint owner backfill (zitadel#12803) (Silvan)
  • [765027e] remove application constraints by app owner (zitadel#12798) (Silvan)
  • [6308539] omit owners on empty unique constraint inserts (zitadel#12785) (Silvan)
  • [6d7878a] Merge commit from fork (gayathri)
  • [c397a60] add owners to unique constraints (zitadel#12740) (Silvan)
  • [482ddc7] forward login_hint to the external IdP (zitadel#12760) (Max Peintner)
  • [473b0fc] verify API credentials at startup instead of in readiness probe (zitadel#12742) (Max Peintner)
  • [ff7b399] publish pgxpool pool stats as metrics (zitadel#12737) (Tim Möhlmann)
  • [d49a665] prevent projections from skipping events (zitadel#12703) (Silvan)
  • [c0b17e0] use UNION of index seeks for ListUsers login equality (zitadel#12701) (Silvan)
  • [8195a58] auto detect google attributes (zitadel#12694) (Tim Möhlmann)
  • [c16a56c] add instance administrator hardening guide (zitadel#12678) (Livio Spring)
  • [41b1114] use authenticated encryption for IDP intent tokens (Livio Spring)
  • [20f0984] check auth method permission on the user's organization (Marco A.)
  • [a53fbc4] authorize IDP linking via enrollment guard, not isSessionValid (gayathri)
  • [739e91e] translate authentication and OTP strings (zitadel#12668) (Matías Racedo)
  • [20f006d] gRPC-Go deps update to 1.83.2 (zitadel#12680) (Marco A.)
  • [a7b3f69] v4.17.1 results and harness fixes (zitadel#12651) (Tim Möhlmann)

Container Images