Skip to content

teleport

v18.9.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 27d Network Security
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

audit bastion certificate cluster database-access firewall
+13 more
firewalls go jumpserver kubernetes kubernetes-access pam postgresql rbac rdp security ssh teleport teleport-binaries

Affected surfaces

auth deps

Summary

AI summary

Broad release touches Description, https://github.com/gravitational/teleport/pull/68099, https://github.com/gravitational/teleport/pull/68052, and https://github.com/gravitational/teleport/pull/68017.

Full changelog

Description

  • Fixed HTTP application access connections returning repeated 403 errors after certificate renewal. When the certificate behind a long-lived connection expires, the proxy now sends Connection: close so the client reestablishes the connection with a renewed certificate instead of reusing a dead one. #68099
  • Add "tsh apps logins" command to query available logins for the given cloud application (currently only AWS is supported). #68052
  • Fixed cloud-hosted Slack plugin exposing credentials in request URLs. #68017
  • Added the Sub CA tctl auth delete-override command, a user-friendly alternative over tctl edit ca_overrides or tctl rm ca_overrides. #68014
  • Fixed potential deadlock when reading access list owners from the cache as the cache becomes unhealthy. #68013
  • Added the Sub CA tctl auth create-override command, a user-friendly alternative over tctl create ca_override.yaml. #67983
  • Fix MFA prompts to show correct --mfa-mode values for webauthn authenticators. #67971
  • Prevent misrouting when multiple apps share the same public address. #67947
  • Fix an issue where the WebUI would prompt for MFA multiple times for admin actions (or outright fail for select commands) when sso is the only allowed second factor on the cluster. #67867
  • Fixed desktop connection failures to Windows 11 / Windows Server 2025 instances. #67483

Enterprise:

  • Add support for rate limiting in the Teleport SCIM Server.
  • Update golang.org/x/crypto to v0.53.0.
  • Updated Teleport Entra ID integration to support delta sync.
  • Only process Okta assignments for groups and apps currently being synced.
  • Prevent user-deletion of Access Lists being synced by Okta integration.

Download

Download the current and previous releases of Teleport at https://goteleport.com/download.

Plugins

Download the current release of Teleport plugins from the links below.

Security Fixes

  • Fixed Slack plugin exposing credentials in request URLs.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track teleport

Get notified when new releases ship.

Sign up free

About teleport

The easiest, and most secure way to access and protect all of your infrastructure.

All releases →

Related context

Earlier breaking changes

  • v18.10.0 Kubernetes ephemeral container addition now requires both exec and patch/update verbs.
  • v18.8.3 Embedded session helper disabled by default; enable via `TELEPORT_UNSTABLE_DISABLE_EMBEDDED_REEXEC=no`.
  • v18.8.0 Roles with unknown fields rejected at create/edit instead of silently dropped.
  • v18.8.0 Teleport Connect automatic updates only; manual downgrades required.

Beta — feedback welcome: [email protected]