Version 1.19.x#

This page shows the changelog for Nubus for Kubernetes 1.19.x:

Version 1.19.0 - 2026-03-31#

This is the twenty-eighth production release of Nubus for Kubernetes.

Upgrade path

For the upgrade to version 1.19.0, your deployment must run on version 1.18.x. For the general steps to upgrade an existing Nubus for Kubernetes deployment, see Upgrade in Univention Nubus for Kubernetes - Operation Manual [1].

Release highlights#

Triage high CVEs across all components

Nubus for Kubernetes 1.19.0 includes triage through VEX information, as well as dependency updates, to address high-severity CVEs across all components.

Migration steps#

You need to apply the following steps before you run the upgrade:

Upgrade OX Consumer at least to 0.36.0

If you have the OX Consumer deployed in your environment, upgrade it to at least version 0.36.0 before you upgrade to Nubus for Kubernetes 1.19.0. The fields of UDM objects returned by the Provisioning Service have changed, and the OX Consumer must be at version 0.36.0 or later to handle them correctly. For installation instructions that also apply to the upgrade, see Install consumer in OX App Suite packaged integration for Nubus for Kubernetes [2].

Changes#

This section lists the changes in 1.19.0 grouped by component in Nubus for Kubernetes.

Portal Service#

  • If you have the portal configured to immediately redirect to the Keycloak login, the self-service /passwordreset modal now redirects to the /newpassword modal instead of the Keycloak login page.

Stack Data#

Nubus no longer writes temporary LDAP objects, such as lock objects, to the transaction log database. This prevents the transaction log from filling up during failed operations, for example when attempting to create a user with a username that already exists.

Provisioning Service#

The fields of UDM objects returned by the Provisioning Service have changed:

uuid:

Removed.

id:

Added. Contains the unique identifier of the object, stored in the univentionObjectIdentifier attribute.

This change only affects Provisioning Consumers that evaluate UDM objects from the data in Event objects. This change doesn’t affect UDM objects returned by the UDM HTTP REST API. For more information, see UDM object in Event objects in Nubus - Customization and Modification Manual [3].

Included errata updates#

Update all components in Nubus for Kubernetes to use the UCS 5.2-5 base image and include bug fixes up to UCS 5.2 erratum 386. For UCS errata updates, see Security and bugfix errata for UCS 5.2. Reference date is 26. March 2026.

The errata updates contain fixes for the following CVEs: The errata updates contain fixes for the following CVEs:

Jinja2
aiohttp
ajv
axios
brace-expansion
keycloak-services
minimatch
nanoid
nginx
nginx-common
orjson
postcss
pydantic
python-multipart
runtime
serialize-javascript
starlette
tornado
urllib3