Skip to content

zitadel

v4.15.2 Security

This release includes 4 security fixes for security teams reviewing exposed deployments.

Published 1mo Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 4 known CVEs

Topics

2fa authentication authorization fido2 fips-140-3 identity
+11 more
login mfa multitenancy oauth2 oidc openid-connect passkeys saml scim sso user

Affected surfaces

auth rbac

Summary

AI summary

Updates Bug Fixes, 4.15.2, and 2026-06-17 across a mixed release.

Full changelog

4.15.2 (2026-06-17)

Bug Fixes

  • always validate exp and iat claims of JWT IdPs (4925fab)
  • client_id verification during code exchange and refresh token flows (5624030)
  • connection handling in setup after migration steps 40, 64 and 70 (#12293) (c53d977)
  • eventstore: allow overwriting resource owner of events (#12261) (a939b84)
  • idp: apply PKCE when building OAuth and OIDC providers (#12247) (ab7c6c0), closes #12036 #12054
  • jwt idp: manage and validate audience (999e2bb)
  • login: accept IDP sessions on passkey registration (#12275) (add46e0)
  • login: load custom font from branding settings and allow in CSP (#12279) (9f1561d), closes #11200
  • remove unnecessary entry from default denylist (#12294) (1ca1fbd)
  • use protected http client for outgoing connections (b6f7808)

Security Fixes

  • always validate exp and iat claims of JWT IdPs
  • client_id verification during code exchange and refresh token flows
  • apply PKCE when building OAuth and OIDC providers (closes #12036, #12054)
  • manage and validate audience for jwt idp

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track zitadel

Get notified when new releases ship.

Sign up free

About zitadel

ZITADEL - Identity infrastructure, simplified for you.

All releases →

Beta — feedback welcome: [email protected]