{
 "schema": "bumplog.app.v1",
 "generatedAt": "2026-07-26T13:02:49.520Z",
 "slug": "authentik",
 "name": "Authentik",
 "repo": "goauthentik/authentik",
 "latestVersion": "version/2026.5.3",
 "safeToUpdate": "safe",
 "rationale": "The release notes describe only bug fixes, a dependency security bump, and documentation improvements — no breaking changes, required migrations, or manual upgrade steps are called out. The two CVEs make applying this patch advisable promptly, but nothing in the notes indicates operator action beyond a standard update.",
 "changelogSummary": "version/2026.5.3 is a patch release focused on bug fixes and security updates. Notable repairs include a fix for SCIM's interactive OAuth incorrectly overriding refresh tokens, a panic in the RADIUS provider log, and an exception in the endpoints/connectors agent when encountering an invalid auth type. The Docker outpost integration form's CA certificate filter is corrected, blueprint application now handles integrity exceptions gracefully, and a polyfill is added for Safari versions below 17.4. Two CVEs (CVE-2026-49443 and CVE-2026-49448) are addressed, and the Django dependency is bumped to v5.2.15.",
 "sourceUrl": "https://github.com/goauthentik/authentik/releases/tag/version/2026.5.3",
 "lastChecked": "2026-07-02",
 "successor": null,
 "url": "https://bumplog.org/apps/authentik/",
 "badge": "https://bumplog.org/badge/authentik.svg",
 "lifecycle": null
}