Skip to content

pangolin

v1.19.2 Breaking

This release includes 1 breaking change for platform teams planning a safe upgrade.

Published 1mo VPN & Tunnels
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

identity-management iot nat-traversal oidc pam private-access
+10 more
proxy remote-access self-hosted single-sign-on ssh tunneling vpn zero-trust zero-trust-network-access ztna

Affected surfaces

auth breaking_upgrade

ReleasePort's take

Moderate signal
editorial:auto 1mo

ReleasePort Layer 1 v1.19.2 fixes several SSH‑related bugs and adds a breaking change that requires migrating host resources to the new SSH resource mode for configuration management.

Why it matters: Severity 70 breaking change mandates migration of all host→SSH configurations before upgrade; bugfixes resolve role‑based access, edge cases, and blueprint errors affecting SREs and developers.

Summary

AI summary

Updates https://pangolin.net/news/1-19-release, https://github.com/fosrl/pangolin/releases/tag/1.19.0, and https://docs.pangolin.net/self-host/how-to-update across a mixed release.

Changes in this release

Breaking High

Requires migration of host resources to new SSH resource mode for config management

Requires migration of host resources to new SSH resource mode for config management

Source: llm_adapter@2026-06-13

Confidence: high

Dependency Medium

Requires Badger Traefik plugin update to v1.4.1 and manual Traefik restart

Requires Badger Traefik plugin update to v1.4.1 and manual Traefik restart

Source: llm_adapter@2026-06-13

Confidence: high

Dependency Medium

Requires Newt version 1.13.0 or greater for browser‑based RDP, SSH, and VNC

Requires Newt version 1.13.0 or greater for browser‑based RDP, SSH, and VNC

Source: llm_adapter@2026-06-13

Confidence: high

Bugfix Medium

Fixes SSH public resource support for non-admin roles

Fixes SSH public resource support for non-admin roles

Source: llm_adapter@2026-06-13

Confidence: high

Bugfix Medium

Fixes SSH public resource respecting ssh action restrictions on roles

Fixes SSH public resource respecting ssh action restrictions on roles

Source: llm_adapter@2026-06-13

Confidence: high

Bugfix Medium

Fixes private SSH resource edge case with missing host

Fixes private SSH resource edge case with missing host

Source: llm_adapter@2026-06-13

Confidence: high

Bugfix Medium

Fixes blueprint server‑side error caused by bad containers

Fixes blueprint server‑side error caused by bad containers

Source: llm_adapter@2026-06-13

Confidence: high

Bugfix Medium

Fixes missing translations in UI/localization

Fixes missing translations in UI/localization

Source: llm_adapter@2026-06-13

Confidence: high

Bugfix Medium

Fixes mode missing in possible migration edge case

Fixes mode missing in possible migration edge case

Source: llm_adapter@2026-06-13

Confidence: high

Full changelog

Read the 1.19 Announcement

Read the full announcement with discussion of new features: Pangolin 1.19: Browser Remote Access — SSH, RDP, VNC & More

What's Changed

Refer to the original 1.19 notes for a complete list of what changed since 1.18.

  • Fix mode missing in possible migration edge case
  • Fix SSH public resource not working with roles other than admin
  • Fix SSH public resource not respecting ssh action restriction on roles
  • Fix missing translations
  • Fix private SSH resource edge case with missing host
  • Fix blueprint server side error with bad containers

How to Update

[!WARNING]
This version includes a new mode of private resource: SSH. If you had previously used host resources and configured the SSH access tab, you will now need to switch these to SSH resources in order to manage the SSH config. If you do not switch they will continue to function as before but you will be unable to adjust settings.

[!IMPORTANT]
1.19 browser-based SSH requires the Badger Traefik plugin to be on the latest version v1.4.1. The migration will automatically do this if it can find the Traefik config in the standard location BUT YOU WILL NEED TO RESTART TRAEFIK TO PULL THE NEW PLUGIN. Otherwise, please ensure your Badger is up to date.

[!IMPORTANT]
Browser-based RDP, SSH, and VNC as well as the new Pangolin SSH mode requires Newt version 1.13.0 or greater.

[!IMPORTANT]
Always back up your config app-data before updating. This will allow you to easily roll back if the update breaks your configuration. You will not be able to easily downgrade otherwise.

View documentation

Breaking Changes

  • SSH private resource mode introduced; existing host resources must be converted to SSH resources to manage SSH config.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track pangolin

Get notified when new releases ship.

Sign up free

About pangolin

Identity-aware VPN and proxy for remote access to anything, anywhere.

All releases →

Related context

Beta — feedback welcome: [email protected]