This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+13 more
Affected surfaces
Summary
AI summaryBroad release touches Description, https://github.com/gravitational/teleport/pull/68099, https://github.com/gravitational/teleport/pull/68052, and https://github.com/gravitational/teleport/pull/68017.
Full changelog
Description
- Fixed HTTP application access connections returning repeated 403 errors after certificate renewal. When the certificate behind a long-lived connection expires, the proxy now sends
Connection: closeso the client reestablishes the connection with a renewed certificate instead of reusing a dead one. #68099 - Add "tsh apps logins" command to query available logins for the given cloud application (currently only AWS is supported). #68052
- Fixed cloud-hosted Slack plugin exposing credentials in request URLs. #68017
- Added the Sub CA
tctl auth delete-overridecommand, a user-friendly alternative overtctl edit ca_overridesortctl rm ca_overrides. #68014 - Fixed potential deadlock when reading access list owners from the cache as the cache becomes unhealthy. #68013
- Added the Sub CA
tctl auth create-overridecommand, a user-friendly alternative overtctl create ca_override.yaml. #67983 - Fix MFA prompts to show correct --mfa-mode values for webauthn authenticators. #67971
- Prevent misrouting when multiple apps share the same public address. #67947
- Fix an issue where the WebUI would prompt for MFA multiple times for admin actions (or outright fail for select commands) when
ssois the only allowed second factor on the cluster. #67867 - Fixed desktop connection failures to Windows 11 / Windows Server 2025 instances. #67483
Enterprise:
- Add support for rate limiting in the Teleport SCIM Server.
- Update
golang.org/x/cryptotov0.53.0. - Updated Teleport Entra ID integration to support delta sync.
- Only process Okta assignments for groups and apps currently being synced.
- Prevent user-deletion of Access Lists being synced by Okta integration.
Download
Download the current and previous releases of Teleport at https://goteleport.com/download.
Plugins
Download the current release of Teleport plugins from the links below.
- Slack Linux amd64 | Linux arm64
- Mattermost Linux amd64 | Linux arm64
- Discord Linux amd64 | Linux arm64
- Terraform Provider Linux amd64 | Linux arm64 | macOS amd64 | macOS arm64 | macOS universal
- Event Handler Linux amd64 | Linux arm64 | macOS amd64
- PagerDuty Linux amd64 | Linux arm64
- Jira Linux amd64 | Linux arm64
- Email Linux amd64 | Linux arm64
- Microsoft Teams Linux amd64 | Linux arm64
Security Fixes
- Fixed Slack plugin exposing credentials in request URLs.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About teleport
The easiest, and most secure way to access and protect all of your infrastructure.
Related context
Related tools
Earlier breaking changes
- v18.10.0 Kubernetes ephemeral container addition now requires both exec and patch/update verbs.
- v18.8.3 Embedded session helper disabled by default; enable via `TELEPORT_UNSTABLE_DISABLE_EMBEDDED_REEXEC=no`.
- v18.8.0 Roles with unknown fields rejected at create/edit instead of silently dropped.
- v18.8.0 Teleport Connect automatic updates only; manual downgrades required.
Beta — feedback welcome: [email protected]