Skip to content

warpgate

v0.25.5 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

bastion bastion-host https https-proxy infrastructure kubernetes
+9 more
mysql mysql-proxy pam postgresql-proxy privileged-access-management proxy rust ssh ssh-server

Affected surfaces

auth

Summary

AI summary

GHSA-3c3w-75j2-7h74 fixes a high‑severity attacker‑crafted login URL redirect vulnerability.

Full changelog

Security fixes

GHSA-3c3w-75j2-7h74

This is a high severity vulnerability. An attacker-crafted Warpgate login URL could lead a user to a redirect page that runs attacker-injected JS code

Features

  • fixed #947 - configurable advertised MySQL server version by @Eugeny in https://github.com/warp-tech/warpgate/pull/2083
    • The new mysql.advertised_version lets you specify the MySQL server version that Warpgate will advertise to clients. Note that the previous hardcoded value of 8.0.0 now defaults to 8.0.3 which disables some ancient compatibility behaviours in various DB clients.

Changes

  • fixed #1842 - tell the SSH client when the session is closed due to inactivity by @Eugeny in https://github.com/warp-tech/warpgate/pull/2082

Fixes

  • #1989 - HTTP: return 401 instead of a redirect for cookie-less fetch by @Eugeny in https://github.com/warp-tech/warpgate/pull/2060
  • fixed #2048 - HTTP: strip cookie domains by @Eugeny in https://github.com/warp-tech/warpgate/pull/2061
  • fixed #2049 - WebSS sessions were never marked as ended by @Eugeny in https://github.com/warp-tech/warpgate/pull/2062
  • fixed #2050 - SSH target menu freezing when running in Docker by @Eugeny in https://github.com/warp-tech/warpgate/pull/2063
  • fixed #1957 - don't offer credentials for disabled SSH auth methods by @Eugeny in https://github.com/warp-tech/warpgate/pull/2071
  • #1962 - handle connection accept errors gracefully by @Eugeny in https://github.com/warp-tech/warpgate/pull/2072
  • fix(logging): emit audit events to the JSON console by @mathieuHa in https://github.com/warp-tech/warpgate/pull/2077
  • fixed #1421 - MySQL/Postgres TLS upgrade race by @Eugeny in https://github.com/warp-tech/warpgate/pull/2081
  • fixed #2065 - rsync/scp/Ansible hang: early channel data dropped by @Eugeny in https://github.com/warp-tech/warpgate/pull/2087

New Contributors

  • @mathieuHa made their first contribution in https://github.com/warp-tech/warpgate/pull/2077

Full Changelog: https://github.com/warp-tech/warpgate/compare/v0.25.4...v0.25.5

Breaking Changes

  • MySQL `advertised_version` default changed from 8.0.0 to 8.0.3, disabling some ancient client compatibility behaviors.

Security Fixes

  • GHSA-3c3w-75j2-7h74 — high severity: attacker‑crafted Warpgate login URL can redirect to a page executing injected JavaScript.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track warpgate

Get notified when new releases ship.

Sign up free

About warpgate

Fully transparent SSH, HTTPS, Kubernetes, MySQL and Postgres bastion/PAM that doesn't need additional client-side software

All releases →

Beta — feedback welcome: [email protected]