| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| zitadel-darwin-amd64.tar.gz | 2026-09-28 | 53.1 MB | |
| zitadel-windows-amd64.tar.gz | 2026-09-28 | 53.0 MB | |
| zitadel-darwin-arm64.tar.gz | 2026-09-28 | 50.7 MB | |
| zitadel-linux-amd64.tar.gz | 2026-09-28 | 52.1 MB | |
| zitadel-linux-arm64.tar.gz | 2026-09-28 | 48.3 MB | |
| zitadel-windows-arm64.tar.gz | 2026-09-28 | 48.5 MB | |
| zitadel-login.tar.gz | 2026-09-28 | 8.1 MB | |
| checksums.txt | 2026-09-28 | 763 Bytes | |
| README.md | 2026-09-28 | 4.0 kB | |
| v4.19.2 source code.tar.gz | 2026-09-28 | 168.2 MB | |
| v4.19.2 source code.zip | 2026-09-28 | 172.8 MB | |
| Totals: 11 Items | 654.8 MB | 0 | |
This release fixes three security vulnerabilities. We recommend all 4.x deployments upgrade.
Security
- GHSA-x4c7-fpcx-w9q6 (high): SAML identity-provider confusion leading to account takeover
- GHSA-jh92-5mrj-p2w2 (high): account takeover through the unsigned Login V2 session cookie
- GHSA-w4gv-rcwj-w6r5 (low): end-user impersonators could impersonate administrators
⚠️ Upgrade notes for the Login UI (Login V2)
Login V2 now signs its session cookie. Before or while upgrading:
- Set
ZITADEL_SESSION_COOKIE_SECRETon the Login UI, for exampleopenssl rand -base64 32. It must be at least 32 characters and the same on all replicas. A shorter value makes the Login UI report not ready. A comma-separated list allows rotating the secret without signing users out. - Without the secret the Login UI keeps working: it derives the signing key from its API credential and logs a deprecation warning at startup. Rotating that credential then signs all users out of the Login UI.
- Users sign in once more: existing cookies carry no signature and are ignored, so users have to sign in to the Login UI again after the upgrade, possibly more than once during a rolling deployment. Application sessions and issued tokens are not affected.
The Docker Compose deployment now sets the secret through LOGIN_SESSION_COOKIE_SECRET. Login V1 is not affected. See Session cookie signing for details, including how to rotate the secret.
4.19.2 (2026-09-28)
Bug Fixes
- idp: reject SAML assertions from a different IdP than the intent (450c056)
- login: sign session cookie entries (6e4a3d4)
- oidc: require admin.impersonation to impersonate administrators (2c37c41)
Performance Improvements
- eventstore: order by sort key as column list instead of row constructor (#12792) (f1891b8), closes #12703 #12789 #12703 #12790 #12789
- eventstore: order events API by creation date (#12789) (76cd246), closes #10626 #12703 #12703 #12703 #12703 #10626
- eventstore: read projection events per event type (#12753) (3a1b76e), closes #12703 #10626 #12703