github gravitational/teleport v15.5.4
Teleport 15.5.4

latest releases: v19.0.0-dev.removewasmpack.14, api/v19.0.0-dev.removewasmpack.14, v19.0.0-dev.removewasmpack.13...
2 months ago

Description

Security fixes

This release also includes fixes for the following security issues:

[Critical] Remote authentication bypass

  • Removed special handling for *ssh.Certificate authorities in the IsHostAuthority and IsUserAuthority callbacks used by x/crypto/ssh.CertChecker. #56254

Resolved an issue that allowed remote SSH authentication bypass on servers with Teleport SSH agents, OpenSSH-integrated deployments and Teleport Git proxy deployments. CVE-2025-49825. Refer to the RCA for the full details.

Other fixes and improvements

  • Updated WindowsDesktop and WindowsDesktopService APIs to use pagination to avoid exceeding message size limitations. #56237
  • Fixed duplicated entries in tctl inventory list when using DynamoDB as cluster state storage. #56184
  • Fixed an issue that could prevent Windows desktop sessions from terminating when the idle timeout was exceeded. #56052
  • Added the teleport-update status --is-up-to-date flag to change the return code based on the update status. #55952
  • Fixed a memory leak in Kubernetes Access caused by resources not being cleaned up when clients terminate watch streams. #55769
  • Updated Go to 1.23.10. #55604

Download

Download the current and previous releases of Teleport at https://goteleport.com/download.

Plugins

Download the current release of Teleport plugins from the links below.


labels: security-patch=yes,security-patch-alts=v15.5.3

Don't miss a new teleport release

NewReleases is sending notifications on new releases.