megachangelog
Security4.19.2

v4.19.2 – Security fixes for SAML, session cookies, and impersonation

This release fixes three security vulnerabilities including SAML identity-provider confusion leading to account takeover, unsigned Login V2 session cookie vulnerability, and unauthorized administrator impersonation. All 4.x deployments should upgrade and configure the new ZITADEL_SESSION_COOKIE_SECRET for Login V2.

This release fixes three security vulnerabilities. We recommend all 4.x deployments upgrade.

Security

⚠️ Upgrade notes for the Login UI (Login V2)

Login V2 now signs its session cookie. Before or while upgrading:

  • Set ZITADEL_SESSION_COOKIE_SECRET on the Login UI, for example openssl rand -base64 32. It must be at least 32 characters and the same on all replicas. A shorter value makes the Login UI report not ready. A comma-separated list allows rotating the secret without signing users out.
  • Without the secret the Login UI keeps working: it derives the signing key from its API credential and logs a deprecation warning at startup. Rotating that credential then signs all users out of the Login UI.
  • Users sign in once more: existing cookies carry no signature and are ignored, so users have to sign in to the Login UI again after the upgrade, possibly more than once during a rolling deployment. Application sessions and issued tokens are not affected.

The Docker Compose deployment now sets the secret through LOGIN_SESSION_COOKIE_SECRET. Login V1 is not affected. See Session cookie signing for details, including how to rotate the secret.


4.19.2 (2026-09-28)

Bug Fixes

  • idp: reject SAML assertions from a different IdP than the intent (450c056)
  • login: sign session cookie entries (6e4a3d4)
  • oidc: require admin.impersonation to impersonate administrators (2c37c41)

Performance Improvements

securitysamlauthenticationsessionimpersonation

Source: original entry ↗

More from ZITADEL

Follow ZITADEL to get its new changes in your feed and email digest.

Fix4.19.4

v4.19.4 Bug Fixes

This release includes bug fixes for the async execution worker context not having the instance ID set, corrects the ID order in the invite code notification handler, and improves handling of finalized unique-constraint backfill and exclusive owner deletes.

bugfixactionsnotificationsdatabase
Improvement4.19.3

Performance improvements for user queries

Improved performance of user listing queries by indexing users by instance and organization, and stopped expanding login names for every ListUsers row to reduce database load.

performancequerydatabaseusers
See all ZITADEL changes →