Version 1.23.x#
Release notes for Nubus for Kubernetes 1.23.x:
Version 1.23.0 - 2026-09-15#
Upgrade path
For the upgrade to version 1.23.0, your deployment must run on version 1.22.x or 1.21.x. For the general steps to upgrade an existing Nubus for Kubernetes deployment, see Upgrade in Univention Nubus for Kubernetes - Operation Manual [1].
Release highlights#
- Guardian returns, based on Cerbos
The Guardian component is back in the Nubus umbrella chart. The new implementation uses Cerbos as its policy decision point. It lays the foundation for fine-grained authorization in future Nubus releases.
- Keycloak container hardened
The Keycloak main container now mounts most volumes read-only. This reduces the attack surface by limiting the paths in the container that are writable at runtime.
- SCIM client improvements
The SCIM client receives several improvements in this release, including object-type specific search endpoints and experimental support for group provisioning.
Migration steps#
This section lists necessary migration steps that may apply to you. You need to run them before the upgrade.
Operators who configured the Notifications API can remove all Helm Chart values under
nubusNotificationsApifrom their custom values files. Nubus no longer provisions the PostgreSQL databasenotificationsapiand its database user. After the upgrade, operators can drop the database and the database user from their PostgreSQL instance.
Changes#
This section lists the changes in 1.23.0 grouped by component in Nubus for Kubernetes.
Guardian#
Nubus for Kubernetes adds the Guardian component to the umbrella chart again.
The new Guardian builds on Cerbos
as its policy decision point.
It provides no functionality yet
and is deactivated by default with the value false
in the Helm Chart value nubusGuardian.enabled.
Activating it doesn’t alter the behavior of your deployment.
Kerberos encryption types#
Nubus for Kubernetes 1.22 announced that the UDM HTTP REST API only writes strong Kerberos encryption types. The change didn’t take effect, and the component kept writing the weak types as well. Version 1.23 fixes this. The UMC server wasn’t affected.
Accounts keep their Kerberos keys until their next password change.
Therefore accounts from 1.22, or from an earlier version,
still have weak keys after the upgrade.
To remove them,
run the remove_krb5key_keytypes script in the UDM HTTP REST API
as described in Dry run command to remove existing weak keys.
Notifications API#
Nubus for Kubernetes removes the Notifications API from the umbrella Helm Chart.
The component is deprecated and no longer part of a Nubus deployment.
The Portal Server feature toggle
nubusPortalServer.portalServer.featureToggles.notifications_api
is deactivated by default with the value false.
Portal Frontend#
The right sidebar of the portal now shows the display name of the signed-in user and falls back to the username if no display name is set. Earlier versions only showed the username.
Included errata updates#
The errata updates contain fixes for the following CVEs:
- binutils
CVE-2026-19582 (unknown)
- binutils-common
CVE-2026-19582 (unknown)
- binutils-x86-64-linux-gnu
CVE-2026-19582 (unknown)
- bsdutils
CVE-2026-53612 (unknown)
CVE-2026-53614 (unknown)
- curl
CVE-2025-10148 (medium)
CVE-2025-14524 (medium)
CVE-2025-14819 (medium)
CVE-2026-3783 (medium)
CVE-2026-3784 (medium)
CVE-2026-7168 (medium)
- libbinutils
CVE-2026-19582 (unknown)
- libblkid1
CVE-2026-53612 (unknown)
CVE-2026-53614 (unknown)
- libctf-nobfd0
CVE-2026-19582 (unknown)
- libctf0
CVE-2026-19582 (unknown)
- libcurl4
CVE-2025-10148 (medium)
CVE-2025-14524 (medium)
CVE-2025-14819 (medium)
CVE-2026-3783 (medium)
CVE-2026-3784 (medium)
CVE-2026-7168 (medium)
- libexpat1
CVE-2026-50219 (medium)
CVE-2026-56131 (medium)
CVE-2026-56403 (medium)
CVE-2026-56404 (medium)
CVE-2026-56405 (medium)
CVE-2026-56406 (medium)
CVE-2026-56407 (medium)
CVE-2026-56408 (medium)
CVE-2026-56409 (medium)
CVE-2026-56410 (medium)
CVE-2026-56411 (medium)
CVE-2026-56412 (medium)
CVE-2026-72522 (medium)
- libexpat1-dev
CVE-2026-50219 (medium)
CVE-2026-56131 (medium)
CVE-2026-56403 (medium)
CVE-2026-56404 (medium)
CVE-2026-56405 (medium)
CVE-2026-56406 (medium)
CVE-2026-56407 (medium)
CVE-2026-56408 (medium)
CVE-2026-56409 (medium)
CVE-2026-56410 (medium)
CVE-2026-56411 (medium)
CVE-2026-56412 (medium)
CVE-2026-72522 (medium)
- libgprofng0
CVE-2026-19582 (unknown)
- liblastlog2-2
CVE-2026-53612 (unknown)
CVE-2026-53614 (unknown)
- liblzma5
CVE-2026-34743 (low)
- libmount1
CVE-2026-53612 (unknown)
CVE-2026-53614 (unknown)
- libpam-modules
CVE-2024-22365 (medium)
- libpam-modules-bin
CVE-2024-22365 (medium)
- libpam-runtime
CVE-2024-22365 (medium)
- libpam0g
CVE-2024-22365 (medium)
- libpq5
CVE-2025-8714 (high)
CVE-2026-14662 (high)
CVE-2026-14664 (high)
CVE-2026-14668 (high)
CVE-2026-14669 (high)
CVE-2026-14670 (high)
CVE-2026-14671 (high)
CVE-2026-14677 (high)
CVE-2026-14679 (high)
CVE-2026-14680 (high)
CVE-2026-15741 (high)
CVE-2026-15742 (high)
CVE-2026-16239 (high)
CVE-2026-18408 (high)
CVE-2026-19385 (high)
CVE-2026-6464 (high)
CVE-2026-6471 (high)
CVE-2026-14663 (medium)
CVE-2026-14666 (medium)
CVE-2026-14678 (medium)
CVE-2026-18024 (medium)
CVE-2026-6470 (medium)
CVE-2026-14673 (low)
CVE-2026-16241 (low)
CVE-2026-6469 (low)
- libpython3.11-minimal
CVE-2026-2297 (medium)
CVE-2026-7774 (medium)
- libpython3.11-stdlib
CVE-2026-2297 (medium)
CVE-2026-7774 (medium)
- libpython3.13-minimal
CVE-2026-7774 (medium)
- libpython3.13-stdlib
CVE-2026-7774 (medium)
- libsmartcols1
CVE-2026-53612 (unknown)
CVE-2026-53614 (unknown)
- libuuid1
CVE-2026-53612 (unknown)
CVE-2026-53614 (unknown)
- login
CVE-2026-53612 (unknown)
CVE-2026-53614 (unknown)
- mount
CVE-2026-53612 (unknown)
CVE-2026-53614 (unknown)
- nginx
CVE-2026-48142 (medium)
- nginx-common
CVE-2026-48142 (medium)
- openjdk-21-jre-headless
CVE-2026-61308 (medium)
CVE-2026-70907 (medium)
CVE-2026-60589 (low)
- openssh-client
CVE-2026-55655 (medium)
- postgresql-client-15
CVE-2025-8714 (high)
CVE-2026-14662 (high)
CVE-2026-14664 (high)
CVE-2026-14668 (high)
CVE-2026-14669 (high)
CVE-2026-14670 (high)
CVE-2026-14671 (high)
CVE-2026-14677 (high)
CVE-2026-14679 (high)
CVE-2026-14680 (high)
CVE-2026-15741 (high)
CVE-2026-15742 (high)
CVE-2026-16239 (high)
CVE-2026-18408 (high)
CVE-2026-19385 (high)
CVE-2026-6464 (high)
CVE-2026-6471 (high)
CVE-2026-14663 (medium)
CVE-2026-14666 (medium)
CVE-2026-14678 (medium)
CVE-2026-18024 (medium)
CVE-2026-6470 (medium)
CVE-2026-14673 (low)
CVE-2026-16241 (low)
CVE-2026-6469 (low)
- python-dotenv
CVE-2026-28684 (medium)
- python3-ecdsa
CVE-2026-33936 (medium)
- python3-jose
CVE-2024-29370 (medium)
CVE-2024-33663 (medium)
CVE-2024-33664 (medium)
- python3-jwcrypto
CVE-2026-39373 (medium)
- python3-rsa
CVE-2020-25658 (medium)
- python3.11
CVE-2026-2297 (medium)
CVE-2026-7774 (medium)
- python3.11-minimal
CVE-2026-2297 (medium)
CVE-2026-7774 (medium)
- python3.11-venv
CVE-2026-2297 (medium)
CVE-2026-7774 (medium)
- python3.13
CVE-2026-7774 (medium)
- python3.13-minimal
CVE-2026-7774 (medium)
- starlette
CVE-2026-48710 (medium)
CVE-2026-48817 (medium)
CVE-2026-54282 (medium)
- util-linux
CVE-2026-53612 (unknown)
CVE-2026-53614 (unknown)