<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bumplog — is it safe to update Authentik?</title>
    <link>https://bumplog.org/apps/authentik/</link>
    <description>Update-safety verdicts for Authentik (goauthentik/authentik), traceable to the GitHub release.</description>
    <language>en</language>
    <atom:link href="https://bumplog.org/apps/authentik/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Authentik version/2026.5.3 — Safe to update</title>
      <link>https://bumplog.org/apps/authentik/</link>
      <guid isPermaLink="false">bumplog:app:authentik:version/2026.5.3:safe</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>Safe to update. The release notes describe only bug fixes, a dependency security bump, and documentation improvements — no breaking changes, required migrations, or manual upgrade steps are called out. The two CVEs make applying this patch advisable promptly, but nothing in the notes indicates operator action beyond a standard update. What changed: version/2026.5.3 is a patch release focused on bug fixes and security updates. Notable repairs include a fix for SCIM&apos;s interactive OAuth incorrectly overriding refresh tokens, a panic in the RADIUS provider log, and an exception in the endpoints/connectors agent when encountering an invalid auth type. The Docker outpost integration form&apos;s CA certificate filter is corrected, blueprint application now handles integrity exceptions gracefully, and a polyfill is added for Safari versions below 17.4. Two CVEs (CVE-2026-49443 and CVE-2026-49448) are addressed, and the Django dependency is bumped to v5.2.15. Source release: https://github.com/goauthentik/authentik/releases/tag/version/2026.5.3</description>
    </item>
  </channel>
</rss>
