Download Latest Version v4.19.4 source code.zip (172.8 MB) Google Add to Preferred Sources
Home / v4.19.2
Name Modified Size InfoDownloads / Week
Parent folder
zitadel-darwin-amd64.tar.gz 2026-09-28 53.1 MB
zitadel-windows-amd64.tar.gz 2026-09-28 53.0 MB
zitadel-darwin-arm64.tar.gz 2026-09-28 50.7 MB
zitadel-linux-amd64.tar.gz 2026-09-28 52.1 MB
zitadel-linux-arm64.tar.gz 2026-09-28 48.3 MB
zitadel-windows-arm64.tar.gz 2026-09-28 48.5 MB
zitadel-login.tar.gz 2026-09-28 8.1 MB
checksums.txt 2026-09-28 763 Bytes
README.md 2026-09-28 4.0 kB
v4.19.2 source code.tar.gz 2026-09-28 168.2 MB
v4.19.2 source code.zip 2026-09-28 172.8 MB
Totals: 11 Items   654.8 MB 0

This release fixes three security vulnerabilities. We recommend all 4.x deployments upgrade.

Security

⚠️ Upgrade notes for the Login UI (Login V2)

Login V2 now signs its session cookie. Before or while upgrading:

  • Set ZITADEL_SESSION_COOKIE_SECRET on the Login UI, for example openssl rand -base64 32. It must be at least 32 characters and the same on all replicas. A shorter value makes the Login UI report not ready. A comma-separated list allows rotating the secret without signing users out.
  • Without the secret the Login UI keeps working: it derives the signing key from its API credential and logs a deprecation warning at startup. Rotating that credential then signs all users out of the Login UI.
  • Users sign in once more: existing cookies carry no signature and are ignored, so users have to sign in to the Login UI again after the upgrade, possibly more than once during a rolling deployment. Application sessions and issued tokens are not affected.

The Docker Compose deployment now sets the secret through LOGIN_SESSION_COOKIE_SECRET. Login V1 is not affected. See Session cookie signing for details, including how to rotate the secret.


4.19.2 (2026-09-28)

Bug Fixes

  • idp: reject SAML assertions from a different IdP than the intent (450c056)
  • login: sign session cookie entries (6e4a3d4)
  • oidc: require admin.impersonation to impersonate administrators (2c37c41)

Performance Improvements

Source: README.md, updated 2026-09-28