This release includes 4 security fixes for security teams reviewing exposed deployments.
Published 1mo
Secrets & Credentials
✓ No known CVEs patched
This release patches 4 known CVEs
Topics
2fa
authentication
authorization
fido2
fips-140-3
identity
+11 more
login
mfa
multitenancy
oauth2
oidc
openid-connect
passkeys
saml
scim
sso
user
Affected surfaces
auth
rbac
Summary
AI summaryUpdates Bug Fixes, 4.15.2, and 2026-06-17 across a mixed release.
Full changelog
4.15.2 (2026-06-17)
Bug Fixes
- always validate exp and iat claims of JWT IdPs (4925fab)
- client_id verification during code exchange and refresh token flows (5624030)
- connection handling in setup after migration steps 40, 64 and 70 (#12293) (c53d977)
- eventstore: allow overwriting resource owner of events (#12261) (a939b84)
- idp: apply PKCE when building OAuth and OIDC providers (#12247) (ab7c6c0), closes #12036 #12054
- jwt idp: manage and validate audience (999e2bb)
- login: accept IDP sessions on passkey registration (#12275) (add46e0)
- login: load custom font from branding settings and allow in CSP (#12279) (9f1561d), closes #11200
- remove unnecessary entry from default denylist (#12294) (1ca1fbd)
- use protected http client for outgoing connections (b6f7808)
Security Fixes
- always validate exp and iat claims of JWT IdPs
- client_id verification during code exchange and refresh token flows
- apply PKCE when building OAuth and OIDC providers (closes #12036, #12054)
- manage and validate audience for jwt idp
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]