Repository navigation
📦 zitadel — v4.19.4
Release type: latest • Commit:
7776c7f
Security:
Image Availability
zitadel
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel |
v4.19.4 · latest |
| Docker Hub | docker.io/hlhd/zitadel |
v4.19.4 · latest |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel |
v4.19.4 · latest |
zitadel-login
| Registry | Reference | Tags |
|---|---|---|
| GitHub Container Registry | ghcr.io/homelabhd/zitadel-login |
v4.19.4 · latest |
| Docker Hub | docker.io/hlhd/zitadel-login |
v4.19.4 · latest |
| cr.pcfae.com | cr.pcfae.com/hlhd/zitadel-login |
v4.19.4 · latest |
Digest pull commands & supply chain artifacts
docker.io/hlhd/zitadel
docker pull docker.io/hlhd/zitadel@sha256:36f5d8cb879578137d0d5dc165a3b832af31a97ea0fc83f43747577d17fa5219
docker.io/hlhd/zitadel-login
docker pull docker.io/hlhd/zitadel-login@sha256:5d6dcd3940ead2d992eabf17311d5ced77df4c0493b6f95397bcf04c4d528f74
cr.pcfae.com/hlhd/zitadel
docker pull cr.pcfae.com/hlhd/zitadel@sha256:36f5d8cb879578137d0d5dc165a3b832af31a97ea0fc83f43747577d17fa5219
cr.pcfae.com/hlhd/zitadel-login
docker pull cr.pcfae.com/hlhd/zitadel-login@sha256:5d6dcd3940ead2d992eabf17311d5ced77df4c0493b6f95397bcf04c4d528f74
ghcr.io/homelabhd/zitadel
docker pull ghcr.io/homelabhd/zitadel@sha256:36f5d8cb879578137d0d5dc165a3b832af31a97ea0fc83f43747577d17fa5219
ghcr.io/homelabhd/zitadel-login
docker pull ghcr.io/homelabhd/zitadel-login@sha256:5d6dcd3940ead2d992eabf17311d5ced77df4c0493b6f95397bcf04c4d528f74
Highlights
- Fork of upstream v4.19.4 carrying the login-v2 project private-labeling fix (zitadel#10692): the OIDC auth request resolves the branding org server-side (org scope, else the requested project's private-labeling setting, else the instance default) and login v2 honors it for branding only — login policy, IdP discovery, and user discovery keep the instance default org.
Notable Changes
Features
- eventstore: remove application constraints by app owner (zitadel#12798) (Silvan)
- database: publish pgxpool pool stats as metrics (zitadel#12737) (Tim Möhlmann)
- telemetry: auto detect google attributes (zitadel#12694) (Tim Möhlmann)
Bug Fixes
- honor project private labeling (zitadel#10692) + self-contained builds (SoFMeRight)
- notification: correct ID order of the invite code sent handler (zitadel#12846) (Livio Spring)
- actions: set instance ID in async execution worker context (zitadel#12730) (Temuri Takalandze)
- skip finalized unique-constraint backfill and exclusive owner deletes (zitadel#12833) (Silvan)
- oidc: require admin.impersonation to impersonate administrators (Tim Möhlmann)
- login: sign session cookie entries (Max Peintner)
- idp: reject SAML assertions from a different IdP than the intent (Marco A.)
- setup step 79 batch unique constraint owner backfill (zitadel#12803) (Silvan)
- eventstore: omit owners on empty unique constraint inserts (zitadel#12785) (Silvan)
- eventstore: add owners to unique constraints (zitadel#12740) (Silvan)
- login: forward login_hint to the external IdP (zitadel#12760) (Max Peintner)
- login: verify API credentials at startup instead of in readiness probe (zitadel#12742) (Max Peintner)
- eventstore: prevent projections from skipping events (zitadel#12703) (Silvan)
- crypto: use authenticated encryption for IDP intent tokens (Livio Spring)
- security: check auth method permission on the user's organization (Marco A.)
- login: authorize IDP linking via enrollment guard, not isSessionValid (gayathri)
- login: translate authentication and OTP strings (zitadel#12668) (Matías Racedo)
Performance
- query: stop expanding login names for every ListUsers row (zitadel#12826) (Silvan)
- query: index users14 by instance and org (zitadel#12830) (Silvan)
- eventstore: order by sort key as column list instead of row constructor (zitadel#12792) (Livio Spring)
- eventstore: order events API by creation date (zitadel#12789) (Livio Spring)
- eventstore: read projection events per event type (zitadel#12753) (Tim Möhlmann)
- query: use UNION of index seeks for ListUsers login equality (zitadel#12701) (Silvan)
Documentation
- add fork note and keep-current warning to README (SoFMeRight)
- fix transparency issue on docs search modal (zitadel#12782) (Federico Coppede)
- migrate to native Fumadocs search & UI fixes (zitadel#12732) (Federico Coppede)
- fix broken links to renamed repository paths (zitadel#12618) (Livio Spring)
- error reference page fails to load, missing basePath in fetch (zitadel#12704) (Rajat Singh)
- add searchable API error reference (zitadel#12502) (Rajat Singh)
- update knowledge gap ID 66 (zitadel#12691) (zitadel-knowledge-bot[bot])
- add instance administrator hardening guide (zitadel#12678) (Livio Spring)
- perf: v4.17.1 results and harness fixes (zitadel#12651) (Tim Möhlmann)
Tests
- fix backfill test (adlerhurst)
Maintenance
- add GitLab CI, scribe assets, preset cache, and the populated fork README (SoFMeRight)
- carry StageFreight governance onto the v4.19.4 base (SoFMeRight)
- Add information for contributors about next gen (zitadel#12741) (Fabienne Bühler)
- gRPC-Go deps update to 1.83.2 (zitadel#12680) (Marco A.)
Other Changes
- Merge commit from fork (gayathri)
Security
Vulnerability details (3 high, 10 medium, 8 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2026-46600 | stdlib | go1.25.14 | 1.26.6 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. |
| High | GO-2026-6355 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global... |
| High | GO-2026-6354 | golang.org/x/crypto | v0.55.0 | 0.56.0 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection... |
| Medium | CVE-2025-24358 | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention mid ... |
| Medium | CVE-2025-47909 | github.com/gorilla/csrf | v1.7.2 | — | Hosts listed in TrustedOrigins implicitly allow requests from the corr ... |
| Medium | CVE-2026-81871 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration |
| Medium | CVE-2026-81872 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission |
| Medium | CVE-2026-56855 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages |
| Medium | CVE-2026-78662 | golang.org/x/crypto | v0.55.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding |
| Medium | GHSA-hjf4-fphr-2h65 | go.opentelemetry.io/otel/sdk/log | v0.19.0 | 0.21.0 | OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full |
| Medium | GHSA-rq77-p4h8-4crw | github.com/gorilla/csrf | v1.7.2 | 1.7.3 | gorilla/csrf CSRF vulnerability due to broken Referer validation |
| Medium | GHSA-w34q-cm8f-9c5x | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | v0.19.0 | 0.21.0 | OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning |
| Medium | GHSA-82ff-hg59-8x73 | github.com/gorilla/csrf | v1.7.2 | — | github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | CVE-2026-81870 | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp | v1.43.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/otel/sdk | v1.44.0 | 1.45.0 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
Full changelog
- [
7776c7f] add GitLab CI, scribe assets, preset cache, and the populated fork README (SoFMeRight) - [
e3216b1] add fork note and keep-current warning to README (SoFMeRight) - [
15d67dc] carry StageFreight governance onto the v4.19.4 base (SoFMeRight) - [
411b264] honor project private labeling (zitadel#10692) + self-contained builds (SoFMeRight) - [
101343a] correct ID order of the invite code sent handler (zitadel#12846) (Livio Spring) - [
03a2469] set instance ID in async execution worker context (zitadel#12730) (Temuri Takalandze) - [
aee8b88] skip finalized unique-constraint backfill and exclusive owner deletes (zitadel#12833) (Silvan) - [
2c6acd8] stop expanding login names for every ListUsers row (zitadel#12826) (Silvan) - [
d378dea] index users14 by instance and org (zitadel#12830) (Silvan) - [
2c37c41] require admin.impersonation to impersonate administrators (Tim Möhlmann) - [
6e4a3d4] sign session cookie entries (Max Peintner) - [
450c056] reject SAML assertions from a different IdP than the intent (Marco A.) - [
eb79d94] Add information for contributors about next gen (zitadel#12741) (Fabienne Bühler) - [
f1891b8] order by sort key as column list instead of row constructor (zitadel#12792) (Livio Spring) - [
76cd246] order events API by creation date (zitadel#12789) (Livio Spring) - [
3a1b76e] read projection events per event type (zitadel#12753) (Tim Möhlmann) - [
57a425f] fix transparency issue on docs search modal (zitadel#12782) (Federico Coppede) - [
e8cdc7d] migrate to native Fumadocs search & UI fixes (zitadel#12732) (Federico Coppede) - [
2903009] fix broken links to renamed repository paths (zitadel#12618) (Livio Spring) - [
bd8b798] error reference page fails to load, missing basePath in fetch (zitadel#12704) (Rajat Singh) - [
556026a] add searchable API error reference (zitadel#12502) (Rajat Singh) - [
8319f12] update knowledge gap ID 66 (zitadel#12691) (zitadel-knowledge-bot[bot]) - [
7695976] fix backfill test (adlerhurst) - [
42cdd5d] setup step 79 batch unique constraint owner backfill (zitadel#12803) (Silvan) - [
765027e] remove application constraints by app owner (zitadel#12798) (Silvan) - [
6308539] omit owners on empty unique constraint inserts (zitadel#12785) (Silvan) - [
6d7878a] Merge commit from fork (gayathri) - [
c397a60] add owners to unique constraints (zitadel#12740) (Silvan) - [
482ddc7] forward login_hint to the external IdP (zitadel#12760) (Max Peintner) - [
473b0fc] verify API credentials at startup instead of in readiness probe (zitadel#12742) (Max Peintner) - [
ff7b399] publish pgxpool pool stats as metrics (zitadel#12737) (Tim Möhlmann) - [
d49a665] prevent projections from skipping events (zitadel#12703) (Silvan) - [
c0b17e0] use UNION of index seeks for ListUsers login equality (zitadel#12701) (Silvan) - [
8195a58] auto detect google attributes (zitadel#12694) (Tim Möhlmann) - [
c16a56c] add instance administrator hardening guide (zitadel#12678) (Livio Spring) - [
41b1114] use authenticated encryption for IDP intent tokens (Livio Spring) - [
20f0984] check auth method permission on the user's organization (Marco A.) - [
a53fbc4] authorize IDP linking via enrollment guard, not isSessionValid (gayathri) - [
739e91e] translate authentication and OTP strings (zitadel#12668) (Matías Racedo) - [
20f006d] gRPC-Go deps update to 1.83.2 (zitadel#12680) (Marco A.) - [
a7b3f69] v4.17.1 results and harness fixes (zitadel#12651) (Tim Möhlmann)