Last 7 days
0
Features: 0
Changes: 0
Fixes: 0
Deprecations: 0
Identity-native infrastructure access platform for servers, Kubernetes, and databases.
Latest Teleport changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this Teleport release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
0
0
8
57
Added multi‑directory sharing and unmount support for Windows RDP sessions, plus AI‑generated session summaries for Windows desktop recordings.
Added new commands and options such as Sub‑CA creation via `tctl auth create`, interactive role prompting, Oracle Cloud region support, and expanded scope features for OpenSSH and session recording.
Breaking change: Kubernetes API server proxy endpoints now require the "proxy" verb; roles must add it to allowed verbs.
Resolved throttling limit in Kubernetes Access (agents now handle more than 5 exec/sec)
Added Device Bound Session Credentials for application access cookies, improving protection against session hijacking and cookie theft (security).
Fixed formatting bug in tsh request show output
Disabled the embedded session helper by default (re‑enable via TELEPORT_UNSTABLE_DISABLE_EMBEDDED_REEXEC env var) due to endpoint‑protection incompatibility.
Fixed multiple bugs: installer script escaping, terminal input logging, Azure join, Windows LDAP discovery, TLS certificate for Amazon Keyspaces, host sudoers on Ubuntu 25.10, and input swallowing in moderated sessions.
Fixed certificate errors in tsh (aws, gcp, azure, proxy) and resolved Windows LDAP discovery conflicts and access‑monitoring graph handling bugs.
Improved performance of predicate expressions, raised app access upstream response header cap to 1 hour, and added internal SCIM PATCH flow optimizations.
SSH service gets major performance gains (lower latency, reduced per‑session memory) and VNet support is added for Linux workstations.
Critical security patches fix high‑severity auth bypass in encrypted session recordings, cross‑node session recording access, and SSRF via AWS database endpoints; users should upgrade Auth and Database services.
Patched high‑severity cross‑node session recording authorization bypass and medium‑severity AWS database SSRF vulnerability; users should upgrade Auth and database services to v17.7.23.
Fixed numerous bugs including audit event loops on expired requests, UI white screen on errors, desktop connection issues during proxy upgrades, VNet start failures, db session redirect, out-of-sequence audit logs, tsh kubectl flag handl...
Added TeleportAccessMonitoringRuleV1 and session summarizer resources to the Kubernetes operator, plus scoped token support to tctl commands.
Fixed web app access in leaf clusters with VNet, corrected desktop session recording UI and metadata summary display, and resolved DB session page redirect to empty page.
Added organization‑level AWS EC2 auto‑discovery, Terraform native flow for EC2 discovery, and static label support for Windows desktops discovered via LDAP.
Fix panic in Enterprise when External Audit Storage is present but not enabled while Access Monitoring is active.
Added --exec-cmd and --exec-arg flags to `tsh proxy kube` for launching custom commands (e.g., k9s) without env var workarounds.
Updated the minimum macOS version to 12 for Teleport and Teleport Connect, breaking compatibility with older macOS releases.
Revised CLI help messages and updated documentation, including GitHub/Kubernetes guide and Helm chart defaults
Fixed multiple bugs: device‑trust username overflow, mixed‑case JSON RPC field handling, Slack plugin token refresh reliability, access‑list prefix query issues, Okta app removal after restart, and SCIM membership change restrictions.
Improved Slack plugin token‑refresh robustness and mitigated a race condition in its refresh logic.
Fixed a CredentialContainer error for Web UI logins with hardware keys on Firefox and patched an Azure OIDC IdP role‑mapping issue (bugfix, security).
Added pid file flag to tbot systemd install command.
Resolved numerous bugs affecting session recording, Access List permissions, AWS Identity Center launch, device‑trust redirects, memory leaks, audit log spam, and more.
Updated Go to 1.24.12 and rustcrypto/rsa dependency to mitigate CVE‑2026‑21895.
Fixed numerous bugs affecting Web UI redirects, Teleport Connect notifications, wildcard DNS SAN issuance, user search, SFTP tilde expansion, AltGr key handling, and memory leaks in access list reminders
Fixed Web UI text editors, service health reason formatting for bot instances, and GitHub/GitLab join token editing issues.
Added identifier first‑login enhancements (username passed to OIDC/SAML providers) and a new guided GitHub Actions Kubernetes wizard for secret‑less workflow setup.
Fixed multiple stability and reliability bugs across Auth Service, event handling, Teleport Connect, VNet handling, Helm chart rollouts, and tbot static keypair creation.
Reduced memory usage and fixed high memory consumption in Application and Auth services, and eliminated data races in interactive Kubernetes sessions.
Added Kubernetes support to Relay Service and shared state between tsh and Teleport Connect, enabling seamless login syncing.
Fixed multiple bugs affecting memory consumption, data races, Kubernetes session handling, DB connections, and encrypted session recording uploads.
Fixed multiple bugs: audit log search with Athena, web upload/download behind load balancers, corrupted private keys, GOAWAY errors from K8s APIs, and Trivy false positives.
Add streamable HTTP and SSE support for MCP Zero Trust Access, enabling secure and auditable HTTP transport connections.
Improved reverse tunnel dialing recovery and enhanced error messages for certificate DNS SAN mismatches and desktop smartcard errors.
Updated containerd dependency to address GHSA‑pwhc‑rpq9‑4c8w security advisory.
Fixed numerous bugs including config file paths, web UI validation for zero‑token bots, MongoDB topology monitoring leaks, Slack plugin crashes, tsh scp issues, startup address conflicts, malformed audit events, Proxy Recording Mode fail...
- Fixed multiple bugs affecting session recordings, MongoDB monitoring, Kubernetes metrics unmarshalling, bot UI validation, and other components.
Added a new Relay Service proxy for SSH/agent traffic and expanded the Web UI with a Workload Identities page, multi‑cluster EC2 discovery, Kubernetes health checks, and ElastiCache Serverless DB support.
Fixed multiple RBAC and access‑list bugs that could cause privilege escalation, including member‑listing collisions and owner permission inheritance issues.
Improved error messages for tsh ssh access denials and offline hosts, and fixed numerous SFTP/ SCP bugs including symlink loops and colon handling.
Fixed several stability issues: SSH/Kubernetes recording player spinner, Proxy memory usage with MySQL REPL, and silent failures on trusted cluster updates.
Updated Datadog Incident Management integration to fix auto‑approval handling and make email matching case‑insensitive.
Fixed numerous stability and integration bugs, including Datadog auto‑approval case handling, Windows Desktop Service crashes, session‑ID multiplexing issues, and peered‑tunnel connectivity; improved error messages and install script rob...
Fixed several bugs including Datadog auto‑approval case handling, tsh play error reporting, Teleport Connect restart UI, Windows Desktop Service crash, audit event compaction overflow, metadata description persistence, and peered‑tunnel ...
Improved robustness of the install node.sh script’s check for an existing Teleport process.
Improved robustness of the install script’s Teleport process check
Fixed numerous bugs including EKS auto‑enrollment via Web UI, panic on bound‑keypair tokens, headless login MFA support, Terraform access list creation, DynamoDB event queries, trusted cluster updates, and Entra ID sync issues.
Fixed multiple bugs: auto‑enrollment of EKS clusters via Web UI, sequential managed updates for client tools, app registration address conflict, and Entra ID sync handling for unsupported usernames.
Added multiple tbot enhancements: default namespace for kubeconfig, Argo CD cluster management, SCIM plugin configuration with OIDC/GitHub, and lock/unlock/delete actions on Bot Details.
Encrypted session recordings can now be encrypted with HSMs or at‑rest encryption settings.
Added new features: namespace spec for tbot Kubernetes secrets, experimental bound keypair joining, Azure VMSS support, new OIDC joining mode for Kubernetes, managed updates for Teleport Connect, and paginated ListDatabases API (deprecat...
Helm charts for Discord, Email, Jira, Mattermost, Microsoft Teams, PagerDuty and Event Handler plugins now support retrieving credentials via tbot.
Fixed desktop connection stall introduced in v18.1.5.
Regression: Windows desktop connections via Web UI fail; workarounds include downgrading proxy or using Teleport Connect.
Fixed multiple Teleport Connect crashes on Windows and added TELEPORT_UNSTABLE_GRPC_RECV_SIZE env var for client‑side gRPC limits.
Fixed multiple bugs affecting Windows desktop registration, revocation checks, MFA error handling, database PKINIT, remote desktop Alt‑Click, Terraform provider race conditions, and other stability issues.
⚠️ Regression: Windows desktop connections via the Web UI are broken; workarounds are to downgrade to 18.1.4 or use Teleport Connect.
Fix missing access‑denied error messages in the Teleport web UI PostgreSQL client
Fixed multiple Terraform provider bugs: race condition causing "does not exist" errors, excessive retries beyond MaxRetries, and handling of non‑empty metadata in autoupdate resources.
Fixed Windows SSH agent forwarding bug and corrected global help flag usage output.
Fix global help flag usage output
Added canary update support for Managed Updates v2, enabling staged updates of up to 5 Linux agents per group
Fix CRL publication for Active Directory Windows desktop access and add headers to generated configuration files
Added new flags and API improvements: `tsh proxy db` listen flag, pagination for Application APIs, and Azure CLI support for App Access commands.
Added new capabilities: MCP server and database proxying, VNet SSH support, identifier‑first login, bound‑keypair joining for Machine ID, Sailpoint SCIM integration, LDAP discovery for Windows desktop, and canary managed updates with UI ...
VNet now has native SSH support and per‑session MFA integration
Added new features: generic SCIM enrollment, bot instance sorting by latest heartbeat, proxy certificate verification skip in Terraform provider, IPv4 VNet DNS support, and updated Pyroscope client timeout/upload rates.
⚠️ Breaking change introduced (affects Access List 'membershipRequires' backward compatibility) – upgrade is blocked until 18.0.2 fixes it.
Fixed backward compatibility issue causing "dynamic" access list type validation errors.
Fixed backward compatibility issue causing "dynamic" access list type validation errors introduced in 17.5.5/18.0.1
Introduced Identity Activity Center, automatic access request reviews, multi‑session MFA for databases, RBAC/device‑trust for SAML apps, database health checks, and Kubernetes CRD enhancements.
Critical remote authentication bypass (CVE‑2025‑49825) fixed by removing special handling for SSH certificate authorities in CertChecker.
Fixed critical remote authentication bypass (CVE‑2025‑49825) affecting SSH certificate authority checks
Fixed broken tbot joining in the Terraform provider and improved tbot health reporting via the /readyz endpoint.
Critical remote authentication bypass (CVE‑2025‑49825) fixed in SSH certificate authority handling.
Fix unsanitized PKINIT Kerberos input that allowed SQL Server host file overwrites (security fix)
Fixed high‑severity Okta integration escalation vulnerability by enforcing required OAuth scopes during plugin creation/update
Introduced Azure SAML IdP support for Azure web console and secretless Bot joining from Azure DevOps pipelines.
Introduces an automatic update mechanism (teleport update binary) to schedule and enforce agent versions, opt‑in for existing agents.
Disabled the “another session is active” prompt when per‑session MFA is enabled, relying on MFA for user confirmation.
Added Prometheus metrics for service cache health and full FIPS agent support
Fixed multiple bugs: Access List import, Proxy cache init errors, Web UI error display, Teleport Connect crash on downgrade, PIV PIN caching, and cluster auth validation.
Fixed UI bugs: malformed user breaking the Users page, removed background color for access‑request resources, and added human‑readable titles for access list audit logs.
Fixed various race conditions, token expiry overwrite, and UI freezes affecting Kubernetes moderated sessions and tsh multi‑node output.
Add a Hardware Key Agent to Teleport Connect with UX improvements and optional PIN caching
Added Hardware Key Agent to Teleport Connect with PIN‑caching and UX enhancements
Introduces an automatic update system allowing admins to schedule and enforce agent versions via new autoupdate resources and the teleport update binary.
Resolved client tool incompatibility with servers older than v16.5.4
Fixed multiple bugs and stability issues: goroutine leak in TLS routing, GKE DNS agent connectivity, Terraform provider permissions and Windows desktop updates, OIDC SSO MFA redirects, SCIM user update, leaf‑cluster conflict handling, an...
⚠️ This version introduces a breaking change (User Kind reporting) and should be skipped until 16.5.5 is released.
Added multiple new features such as Managed Updates v2 autoupdate config in the Terraform provider, PostgreSQL role selection in the Web UI, expression support in Bot RBAC rules, increased bot certificate TTL to 7 days with a new flag, a...
Fixed managed updates v1 bug that blocked updaters v2 and AWS integrations when weekdays were set in cluster maintenance config.
Fixed a bug where managed updates v1 prevented updaters v2 and AWS integrations from updating when weekdays were set in the maintenance config.
Workload ID attestors for Kubernetes, Podman, and Docker now capture container image digests.
Fixed web UI and tsh issues when a SAML metadata URL is slow to respond
Added Oracle join method and container image digest capture for Workload Identity, plus support for WorkloadIdentity in the Teleport Kubernetes Operator
Fixed multiple stability and performance issues including DynamoDB throttling, high CPU in reverse tunnels, and crashes in audit log trimming and group database handling.
Added extra tracking metadata to updates and support custom claims in JWT SVIDs (Workload ID).
Fixed DynamoDB backend event stream throttling for high‑shard tables.
Reduced resource consumption and latency for tsh ssh
Fix bug where discovery service fails to configure nodes when managed updates v2 is enabled.
Introduces opt‑in automatic update mechanism with autoupdate config and version resources, using the new teleport‑update binary.
Added Oracle RDS Kerberos DB access, AWS integration status dashboard, and Windows desktop support for both AD and local logins.
Fixed multiple bugs: systemd service on CentOS 7, panic during audit log trimming, crash on group DB errors, desktop session recording proportions, Terraform provider data sources, Slack plugin enrollment, and UI rendering of Autoupdate ...
Added workload attestation for Docker and Podman, a new join method flag for the configure command, and enabled the event handler to generate certificates for non‑resolvable DNS names.
Updated golang.org/x/net to address CVE‑2025‑22870
- Added workload identity enhancements: predicate language in templates, X509 revocation support, and non‑FIPS AWS endpoints for IAM/STS.
Escape user-provided labels in enrollment scripts and add JSON response support to the public‑certificate export API.
Updated Go runtime to 1.23.7 and added new Prometheus metrics for Machine ID renewal loops.
Fixed RPM packaging bugs in 17.3.0 that caused upgrade failures and missing /usr/local/bin symlinks; 17.3.1 should be used.
Introduces an opt‑in automatic update system with a new `teleport update` binary and autoupdate config/resources
Security updates: upgraded go‑jose/v4 to 4.0.5 and /x/crypto, /x/oauth2 to fix CVE‑2025‑27144, CVE‑2025‑22869 and CVE‑2025‑22868.
Fixed several broken UI actions (Download Metadata, Refresh, Microsoft Teams download) and resolved an unexpected JSON input error in API calls.
Fixed critical security issues including arbitrary file reads on SSH nodes, added TLS peer certificate cluster‑name verification, and introduced an escape hatch for non‑FIPS AWS endpoints.
Security hardening: fixed arbitrary file read vulnerability, added TLS peer certificate cluster name verification, blocked remote identity auth in git forwarder, and updated OpenSSL to 3.0.16.
Fixed critical security issues: arbitrary file reads on SSH nodes and TLS peer certificate cluster name validation to prevent auth bypasses; added securityContext to the tbot Helm chart.
Fixed arbitrary file read vulnerability on SSH nodes.
Added support for multiple active CAs, wildcard workload identity issuer preset, and enriched role presets with default GitHub permissions and git server resource kind.
Added per‑session MFA using external IdPs and full SSO MFA support in the Web UI, enhancing security
Fixed WebAuthn attestation for Windows Hello, client tools auto‑update alias recursion, AWS SigV4 parsing, Database Service ARN handling, and agentless node routing issues.
Fixed several security and compatibility bugs: WebAuthn attestation for Windows Hello, AWS SigV4 parsing, client‑tools auto‑update alias recursion, and Okta SSO UI status.
Fixed a panic crash in the EKS Auto Discovery component.
Fixed numerous bugs: log quoting errors, S3 bucket region fetching, shutdown panic when SQS is disabled, ssh port‑forward hanging, Helm chart config issues, UI login redirection, Postgres auto‑user provisioning syntax, Oracle DB cleanup,...
Fixed numerous bugs across Azure join throttling, S3 bucket region handling, shutdown panics, Helm chart config, Access List role locking, session playback URLs, Oracle DB cleanup, and Access Graph retries
Fixed several issues: Azure join throttling, Teleport Connect Oracle support, log quoting errors, event‑handler error loops, and AWS SSM session failures with KMS encryption.
Fixed syntax error in Postgres auto‑user provisioning, preventing misleading debug logs and clarifying required ADMIN role for upgraded databases
Fix compatibility bug preventing v16 Teleport from connecting to v17.1.x clusters
Fixed WebUI access‑denied error when accessing applications.
17.1.0 introduced a regression causing SSH server heartbeats to disappear after a few minutes
Fix regression where SSH server heartbeats disappear (skip 17.1.0) and update golang.org/x/net to address CVE‑2024‑45338.
Updated golang.org/x/net to v0.33.0, fixing CVE‑2024‑45338 (security).
Updated golang.org/x/crypto to v0.31.0, addressing CVE‑2024‑45337.
Updated golang.org/x/crypto to v0.31.0, fixing CVE‑2024‑45337 (security).
Updated golang.org/x/crypto to v0.31.0, fixing CVE‑2024‑45337 (security).
Fixed cluster‑joining bugs for Kubernetes (including token audience handling) and corrected proxy peering address and Helm chart token‑mount issues.
Fixed cluster joining bug on certain Kubernetes clusters and corrected UI re‑rendering when filtering Unified Resources.
Fixed cluster‑joining bug on certain Kubernetes clusters introduced in v16.4.9.
Restored ability to disable MFA for local users and added resource label configuration in the operator chart.
Added configurable resource labels in the Teleport Operator chart and support for delegated Bitbucket Pipelines joining; Kubernetes cluster joins now accept tokens scoped to the cluster name.
Fixed multiple Helm chart and Kubernetes operator bugs (token mount with ArgoCD, serviceAccount name usage, OIDCConnector max age, duplicate session recordings, YubiKey false positives).
Added features: delegated Bitbucket Pipelines joining, Azure VM cross‑subscription joining, JWKS config for GitHub, and searchable SSH session text in Web UI and Teleport Connect.
Added Azure VM join support across subscriptions and direct JWKS configuration for GitHub enterprise joins.
Refreshed web UI with improved access‑list UI, dynamic Windows desktop registration, and image rendering in web SSH sessions.
Added a searchable cluster dropdown in the Web UI and introduced new commands/flags such as `tsh resolve` and delimiter support for `tsh ssh`; also added a warning in `tctl edit` and an env var to force proxy address usage.
Fixed a range of bugs including duplicate Kubernetes session recordings, UI errors for Add Application and access requests, U2F authenticator errors, and issues with migrations, home directories, and idle time handling.
Fixed numerous bugs including S3 bucket creation in audit storage, RBAC session listing leakage, flag parsing in tsh logout, and metric overshoot after keepalive errors.
High‑severity security fix addressing privilege persistence in Okta SCIM‑only integrations, preventing unassigned users from retaining roles.
Fixed a high‑severity privilege persistence issue in Okta SCIM‑only integration that could let unassigned users retain roles, requiring an upgrade to 15.4.19+.
Extended Discovery Service for cross‑project resource discovery and added new APIs (AccessMonitoringRule, AWS Terraform, Teleport Connect SSH‑agent controls, JWT enhancements).
Added new CLI capabilities and config flags (access‑monitoring rule listing, kubeconfig context display, AWS HA bastion instance type, SSH‑agent handling, device‑trust enforcement, and SAML connector handling)
Fixed numerous bugs affecting access request display, file uploads, SAML connector creation, SAML IdP cache, Kubernetes access, host user creation, session joining, Firestore backend reads, audit event trimming, and Helm chart annotation...
Fixed panic in the self‑hosted PagerDuty plugin and a crash in the Teleport Policy GitLab integration.
Kubernetes Operator can now read client secrets from Kubernetes Secrets for GithubConnector and OIDCConnector.
Added secret‑less Machine ID joining for HCP Terraform/Terraform Enterprise and a new Terraform Cloud joining method
Fixed Kubernetes access bug causing metav1.PartialObjectMetadata errors, host user creation failures, session join issues, and Firestore backend read problems.
Added out-of-band host user creation support in the SSH service
- Fixed multiple regressions affecting Firestore backend, Slack notifications, and Teleport Web UI role handling.
Updated Go to 1.22.7 and OpenSSL to 3.0.15.
- Fixed numerous bugs affecting debug service toggling, duplicate session recordings, certificate re‑issuance, session playback, IAM/TLS joins, proxy termination, WebSocket upgrades, sudoers handling, kernel checks, and interactive sessi...
Added API resources for auto‑update and Terraform installer support, plus extended Kubernetes to use custom cluster domains.
Fixed multiple stability and security issues, including random proxy disconnects, sudoers leakage, session hangs, WebSocket upgrade failures, and kernel version checks.
High‑severity stored XSS vulnerability in Teleport's SAML IdP fixed; upgrade auth and proxy servers for self‑hosted IdP usage.
Added optional Network Level Authentication (NLA) for Windows desktop RDP connections and Logrotate integration for automatic log file reopening
Fixed a high‑severity Stored XSS vulnerability in the SAML IdP service‑provider registration, requiring an upgrade for clusters acting as an IdP.
Fixed a high‑severity stored XSS vulnerability in Teleport's SAML IdP that could let admins register malicious service providers and hijack user sessions
Updated Go toolchain to 1.22.6 and upgraded dependencies, including a go‑retryablehttp update fixing CVE‑2024‑6104; added security hardening such as binary signing verification, DoS mitigation, and redirect protection for apps
Enhanced terminal copy/paste shortcuts (Ctrl+Shift+C/V) and added ConPTY support with env vars for better resizing on Windows.
Improved tsh SSH performance for concurrent execs
Added Kubernetes Workload Attestation, SSO device‑trust support, VNet background item, and TERM_PROGRAM env vars in Teleport Connect.
Added SSO client redirect CIDR option, configurable Machine ID via Kubernetes secrets, and an application tunnel service for Machine‑to‑Machine access.
Fixed auth server panic on backend connectivity loss and reduced event handler deadlock probability when processing session recordings.
Added application tunnel service for Machine ID and new CLI flags (tsh play idle‑skip, tbot systemd install), plus support for existing ingresses and Rocky/AlmaLinux enrollment in the UI.
Introduced a refreshed Teleport logo across the web UI, marketing site, and branding assets.
Add proxy template support in tsh ssh and new configurable options in AMI and Helm charts (event handler event types, kube‑agent extraLabels, optional env‑var sourcing)
Added audit events for discovery config actions and expanded Kubernetes support (non‑default domains, MFA‑await on expired certs, leaf‑cluster dialing via tbot).
Omit control plane services from inventory list output for Cloud Hosted instances.
Fixed a medium‑severity SCIM client vulnerability that could overwrite Teleport system roles in Enterprise Okta integration (also patches CVE‑2024‑6104 via retryablehttp update).
Fixed medium‑severity security issue where a SCIM client could overwrite Teleport system roles (Okta integration) and updated go‑retryablehttp to address CVE‑2024‑6104.
Added UI editing of user traits, support for crown‑jewel resource, and improved log rotation in Teleport Connect.
Fixed numerous bugs across services, including gRPC cert handling, health endpoints, UI logout, panic prevention, DB user listing, and session recording issues.
tctl now skips its config file when the auth service is disabled, preferring identity files or tsh profiles.
Improved search and predicate/label based dialing performance for large clusters under high load.
Introduces Teleport VNet for virtual IP subnet/DNS proxy, Device Trust enforcement for the Web UI, and per‑session MFA across UI, CLI, and Connect.
Added a new fdpass binary and introduced the Machine ID SSH multiplexer service, greatly reducing SSH resource usage and improving performance
Multiple bug fixes covering Desktop Access resize during MFA, DB user listing, file upload/download, metadata fetching, Helm chart rollouts, UI dropdown height, app health reporting, and DynamoDB audit log panics.
Added notification routing rules for Slack access requests, GCP Spanner database support, and Unix workload attestation for SVID restriction.
Fixed multiple high‑severity security flaws, including unrestricted SSO redirects, CockroachDB authorization bypass, long‑lived connections with expired certificates, and privilege escalation via PagerDuty and SAML IdP integrations.
Resolved “no roles configured” error preventing access request creation in Teleport Connect.
Patched several high‑severity security flaws, including unrestricted SSO redirects, CockroachDB auth bypass, expired‑certificate connection persistence, PagerDuty and SAML IdP privilege escalations, and forced HTTPS localhost callbacks f...
Fixed multiple high‑severity security issues: unrestricted SSO redirect, CockroachDB RBAC case bypass, expired‑certificate connection persistence, and privilege escalation in PagerDuty and SAML IdP integrations.
Fixed bug preventing tsh proxy kube certificate renewal for leaf clusters via root
Added active sessions page visibility for users with join permissions and included lock target in lock deletion audit events
- Fixed UI and permission issues: Windows Desktop resize behavior, active sessions page visibility, account authentication method indicators, and helm chart operator registration.
Security hardening: fixed SSO bypass, enforced passwordless policy, added TPM join method and hardware‑key support for agentless connections, and prevented deletion of AWS OIDC integrations used by external audit storage.
Added a paginated API for the Roles UI, improving load performance on large clusters
Extend proxy templates to resolve target hosts via predicate expressions or fuzzy matching.
Fixed multiple bugs and security vulnerabilities, including Helm chart issue, zip upload limit, data race, resource leak, and patched several CVEs.
Add new audit log event for denied join requests and a Prometheus metric for Teleport control‑plane API usage
Patched multiple CVEs and fixed security‑related bugs (CVE‑2024‑32650, CVE‑2023‑45288, CVE‑2024‑32473, cosign updates).
Added new kube exec proxy mode for tsh, automatic role access requests, and Machine ID workload identity support for legacy systems.
Teleport Connect now shows the full list of recent connections (removing the 10‑item cap) and re‑enables the desktop wallpaper flag.
Added a paginated, searchable, and filterable Access Requests UI with automatic database request prompts and start‑time scheduling.
Patched phishing vector in install/join scripts and ensured MFA prompts appear for session joins.
Patched critical security flaws: prevented phishing link code execution, ensured MFA prompts on session join, and blocked invalid access request start times.
Fixed security problems including phishing link execution, MFA prompt issues, and SSO login bugs, and added audit events for config changes.
Fixed discovery script crash when jq is missing.
Performance improvements for node listing in tsh and tctl
Fixed AWS IAM permission errors that blocked access to AWS RDS, Redshift, Elasticache, and MemoryDB when the discovery service was enabled alongside the DB service.
Fixed AWS IAM permission bug that prevented access to RDS, Redshift, Elasticache, and MemoryDB when the discovery service was enabled alongside the DB service.
Fix auth server panic when Access Graph is enabled in discovery service
Fixed auth server panic occurring when Access Graph is enabled in the discovery service.
Improved error messages for duplicate resource creation or missing-update failures.
Fixed a panic in the Teleport auth server when Access Graph is enabled in the discovery service.
Improved error messages when creating resources that already exist or updating resources that were removed
Added identity file support for `tsh login` and improved error messages for resource creation/update failures.
Added remote port forwarding for Teleport nodes.
Improved error messaging for resource creation/updating and added audit UI truncation for long role lists; fixed bugs in MFA admin actions, access request start dates, and Jira plugin error logging.
Patched CVE-2024-27304 (Postgres driver) and CVE-2024-27303 (Electron builder) addressing security vulnerabilities.
Raised concurrent connection limits for Teleport Cloud regions and proxy‑peered clusters
Fixed numerous critical bugs: Kubernetes API spec compliance, tsh kube credential relogin, DynamoDB event overwrites, private‑key policy handling, and various panics and regressions across tsh, tbot, and the proxy.
Fixed bugs affecting automatic updates, tsh kube credential re‑login, systemd service compatibility, password changes, SAML IdP generation, and session listing output.
Fixed panic when older tsh or proxy changes an access list and corrected private‑key‑policy errors to trigger automatic re‑login.
Added a lightweight standalone tbot Docker image and dynamic mouse pointer updates for remote desktop sessions.
Published a distroless tbot image and added a new ssh service.recording.root configuration for custom cgroup slices.
Fixed panic in `tsh status` and multiple stability bugs (memory leak in tbot, CLI resizing, idle desktop handling, app redirection loop, U2F key handling).
Fixed multiple stability and panic issues (tsh status, Assist UI, desktop clipboard, idle desktop connections) and improved graceful upgrade reliability.
Fixed multiple stability issues including CLI app resizing on Windows, a tbot memory leak, tsh panic on missing WebAuthn DLL, and app session resource leaks
Updated OpenSSL to 3.0.13 and added MFA device lock verification, enhancing security.
Added SCIM support for Okta integration (cloud and web UI).
Updated OpenSSL to 3.0.13 and rewrote the tsh FIDO2 backend for better responsiveness and reliability.
Adds major features: new high‑performance RDP engine, Linux Device Trust (TPM), automatic SSH connection resumption, RDS auto‑discovery, EKS enrollment, AWS KMS CA storage, MFA required for admin actions, Teleport Connect MFA and app sup...
Fixed node routing when using public addresses.
Fixed routing to nodes via their public address
Added several new capabilities: selecting database roles via `tsh`, callback flag for `tsh login`, Database Roles column in `tsh db ls`, auto‑enrolling RDS discovery in UI, version server in proxy for auto‑agent upgrades, and future assu...
Added several features: access lists can now grant roles and traits, proxy can host a version server for automatic agent upgrades, access list caching to improve performance, new certificate extensions for Machine ID bots, and an insecur...
Updated Go runtime to 1.20.13.
Security hardening: restrict SFTP for normal users, fix SSRF via reverse tunnel, filter macOS DYLD variables, bump golang.org/x/crypto to address CVE‑2023‑48795, and add lock/MFA/Webauthn protections.
Security hardening: restrict SFTP for normal users, fix SSRF via reverse tunnel, filter macOS DYLD variables, prevent Access List privilege escalation, and upgrade crypto library to address CVE‑2023‑48795.
Added several security fixes including SFTP restrictions for normal users, SSRF mitigation in reverse tunnels, macOS DYLD variable filtering, and protection against Access List privilege escalation
Introduced several new UI and integration features: Show All Labels button, ServiceNow auto‑approval flow, guided SAML entity descriptor creation, connection test for Connect My Computer, and direct Slack notifications for access requests.
Added several new features including email‑based credential reset and invite UI, insecure host user creation mode, and default RDP port for desktop connections;
Added security and usability features: prevented Cloud tenants from being leaf clusters, introduced insecure drop‑host user mode, defaulted desktop connections to RDP port 3389, added cluster‑auth shortcuts, and used desktop name instead...
Stability improvements: Fixed numerous panics and regressions (deleted app server, arm32 binaries, GCP VM IP discovery, Athena audit queries, bot access request view, EKS IAM issues, kubeconfig signing, etc.).
External Audit Storage lets Cloud customers store audit logs and session recordings in their own AWS accounts.
Device trust data collection is now concurrent on Windows
Fixed critical security issues: blocked LD_PRELOAD env injection in SFTP, prevented IP spoofing via PROXY protocol headers, and patched third‑party OpenTelemetry DoS vulnerability.
Added enterprise‑only Okta integration that auto‑creates SSO connectors and syncs users
Added Teleport Access Graph integration, IAM authentication for Amazon MemoryDB, list view option for unified resources, and support for binary‑encoded PostgreSQL audit parameters.
Added IAM Authentication for Amazon MemoryDB, binary‑encoded PostgreSQL bind‑parameter audit logging, and splitting of large desktop recordings into multiple export files.
Fixes two medium‑severity security issues: prevents LD_PRELOAD and other dangerous env vars from being forwarded during SFTP subcommand execution, and blocks IP spoofing by enforcing SSH protocol prefix when PROXY headers are enabled.
Fixed two medium‑severity security issues: blocked dangerous LD_PRELOAD env vars in SFTP subcommands and prevented IP spoofing on proxies by enforcing the SSH protocol prefix
Fixed UI layout issue in Connect and added Web UI redirect to login when session cookie is missing
Fix: top bar layout no longer breaks on narrow windows in Connect.
Updated multiple language dependencies (Go, JS, OpenTelemetry, etc.) to patch a wide range of CVEs including HTTP/2 stream cancellation, DoS, ReDoS, and prototype pollution vulnerabilities.
- Introduces Connect My Computer for one‑click personal machine enrollment, plus new UI features like resource pinning, access monitoring, EC2 Instance Connect, and periodic access‑list reviews.
Added bot support for access request reviews, new notifications, and UI enhancements for Identity Governance & Security.
Critical security fix addressing privilege escalation via RecursiveChown in automatic Linux user creation.
Critical security fix addressing privilege escalation via RecursiveChown in automatic Linux host user creation.
Fix a critical privilege escalation bug in automatic Linux host user creation (RecursiveChown race condition).
Critical privilege escalation vulnerability fixed in automatic Linux user creation (RecursiveChown race condition).
Added host sudoers management without user creation, PostHog and Access List usage events, initial ServiceNow plugin, and JWT‑only‑traits rewrite for web apps.
Added host sudoers management, Access List usage events, JWT trait‑only rewrite, IneligibleStatus fields, and AWS EC2 IMDSv2 support.
Added support for AWS EC2 IMDSv2 in the installer script and inventory metadata collection
Add access lists, unified resource view, and advanced audit log with Amazon S3/Athena support; expand database access (ClickHouse, Oracle) and Kubernetes capabilities (auto‑discovery, extended per‑resource RBAC, TLS routing in Terraform ...
Fixed four critical security issues including privilege escalation via host user creation, insufficient auth token verification, Windows config file misuse, and SAML IdP XSS
Fixed four critical security vulnerabilities: host user creation race condition, insufficient auth token verification for self‑hosted DB certificates, untrusted Windows config file, and SAML IdP XSS.
Fix three critical security issues: privilege escalation via automatic Linux host user creation, improper auth token validation for self‑hosted DB certificates, and unsafe global tsh config loading on Windows.
Upgrade Go runtime to v1.20.8.
Fixed desktop discovery IPv6 mapping, macOS shell spawning, connection leaks, DNS error handling, and MFA desktop access issues.
Fix multiple issues: WebAuthn Windows registration, leaf‑cluster query‑parameter trimming, UI integration tile wrapping, tsh db connect defaults, Azure auto‑discovery credentials, macOS shell launch, IPv6 mapping in desktop discovery, an...
Fixed OIDC authentication regression and other bugs (Oracle GUI flow, connection monitor leaks).
Multiple bug fixes across components including S3 metrics, SSH session error reporting, review request handling, GKE discovery panics, PAM memory leak, ElastiCache/MemoryDB auth, Firestore update deletions, LDAP DNS handling, SAML parsin...
Fix crash in Teleport cluster Helm chart with DynamoDB autoscaling and resolve multiple bugs (S3 metric name, Review Requests, SSH session error reporting, tsh aws ssm start session, access request maxDuration).
Fixed numerous bugs across S3 metrics, SSH sessions, discovery service, LDAP, PAM memory leak, Firestore, desktop access, audit logging, and command output formatting
Added ability to create host users with specific UID/GID and introduced new configuration options such as skipConfirm for headless approvals, JWT claim rewriting, and stricter Database URL validation
Added new integrations: Opsgenie auto‑approval flow, hosted Jira, and AWS OpenSearch configurator support.
Added new Prometheus metrics for access request creation and Kubernetes access, plus UI enhancements (auto‑deploy DB service via ECS Fargate and headless approval UI in Teleport Connect)