v4.19.2 – Security fixes for SAML, session cookies, and impersonation
This release fixes three security vulnerabilities including SAML identity-provider confusion leading to account takeover, unsigned Login V2 session cookie vulnerability, and unauthorized administrator impersonation. All 4.x deployments should upgrade and configure the new ZITADEL_SESSION_COOKIE_SECRET for Login V2.
This release fixes three security vulnerabilities. We recommend all 4.x deployments upgrade.
Security
- GHSA-x4c7-fpcx-w9q6 (high): SAML identity-provider confusion leading to account takeover
- GHSA-jh92-5mrj-p2w2 (high): account takeover through the unsigned Login V2 session cookie
- GHSA-w4gv-rcwj-w6r5 (low): end-user impersonators could impersonate administrators
⚠️ Upgrade notes for the Login UI (Login V2)
Login V2 now signs its session cookie. Before or while upgrading:
- Set
ZITADEL_SESSION_COOKIE_SECRETon the Login UI, for exampleopenssl rand -base64 32. It must be at least 32 characters and the same on all replicas. A shorter value makes the Login UI report not ready. A comma-separated list allows rotating the secret without signing users out. - Without the secret the Login UI keeps working: it derives the signing key from its API credential and logs a deprecation warning at startup. Rotating that credential then signs all users out of the Login UI.
- Users sign in once more: existing cookies carry no signature and are ignored, so users have to sign in to the Login UI again after the upgrade, possibly more than once during a rolling deployment. Application sessions and issued tokens are not affected.
The Docker Compose deployment now sets the secret through LOGIN_SESSION_COOKIE_SECRET. Login V1 is not affected. See Session cookie signing for details, including how to rotate the secret.
4.19.2 (2026-09-28)
Bug Fixes
- idp: reject SAML assertions from a different IdP than the intent (450c056)
- login: sign session cookie entries (6e4a3d4)
- oidc: require admin.impersonation to impersonate administrators (2c37c41)
Performance Improvements
- eventstore: order by sort key as column list instead of row constructor (#12792) (f1891b8), closes #12703 #12789 #12703 #12790 #12789
- eventstore: order events API by creation date (#12789) (76cd246), closes #10626 #12703 #12703 #12703 #12703 #10626
- eventstore: read projection events per event type (#12753) (3a1b76e), closes #12703 #10626 #12703
Source: original entry ↗
More from ZITADEL
Follow ZITADEL to get its new changes in your feed and email digest.
v4.19.4 Bug Fixes
This release includes bug fixes for the async execution worker context not having the instance ID set, corrects the ID order in the invite code notification handler, and improves handling of finalized unique-constraint backfill and exclusive owner deletes.
Performance improvements for user queries
Improved performance of user listing queries by indexing users by instance and organization, and stopped expanding login names for every ListUsers row to reduce database load.
Fixed batch unique constraint owner backfill in setup step 79
Corrected a bug in setup step 79 related to batch unique constraint owner backfill to ensure database consistency during initialization.