megachangelog
Fix4.19.4

v4.19.4 Bug Fixes

This release includes bug fixes for the async execution worker context not having the instance ID set, corrects the ID order in the invite code notification handler, and improves handling of finalized unique-constraint backfill and exclusive owner deletes.

4.19.4 (2026-10-01)

Bug Fixes

  • actions: set instance ID in async execution worker context (#12730) (03a2469), closes #11985
  • notification: correct ID order of the invite code sent handler (#12846) (101343a)
  • skip finalized unique-constraint backfill and exclusive owner deletes (#12833) (aee8b88), closes #12831 #12834
bugfixactionsnotificationsdatabase

Source: original entry ↗

More from ZITADEL

Follow ZITADEL to get its new changes in your feed and email digest.

Improvement4.19.3

Performance improvements for user queries

Improved performance of user listing queries by indexing users by instance and organization, and stopped expanding login names for every ListUsers row to reduce database load.

performancequerydatabaseusers
Security4.19.2

v4.19.2 – Security fixes for SAML, session cookies, and impersonation

This release fixes three security vulnerabilities including SAML identity-provider confusion leading to account takeover, unsigned Login V2 session cookie vulnerability, and unauthorized administrator impersonation. All 4.x deployments should upgrade and configure the new ZITADEL_SESSION_COOKIE_SECRET for Login V2.

securitysamlauthenticationsessionimpersonation
See all ZITADEL changes →