We'll be publishing three security Issues (CVE-2026-47201, GHSA-wr38-7xg8-fqxr, GHSA-xp7f-xjjx-gwm8) and accompanying fixes on 2026-05-28, 14:00 UTC with the Severity levels High and Critical.
These releases will also contain various other minor security improvements. Fixed versions 2025.12.6 and 2026.2.4 and 2026.5.1 will be released alongside a partial workaround for previous versions.
For more info, see the authentik Security policy here:
https://goauthentik.io/docs/security/policy.