# Authelia v4.39.21 - Product: Authelia (https://whatsnew.fyi/product/authelia) - Vendor: Authelia - Date: 2026-09-03 - Version: v4.39.21 - Original notes: https://github.com/authelia/authelia/releases/tag/v4.39.21 - Permalink: https://whatsnew.fyi/product/authelia/releases/v4.39.21 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **fixed** — Fix missing and misleading API endpoints - **fixed** — Fix pooled client skip in authentication - **fixed** — Fix stale user database aliases in authentication - **fixed** — Remove unnecessary read lock in authentication - **fixed** — Fix deprecated wildcard consistency and DID in authorization - **fixed** — Add authelia.pam to scopes in schema configuration - **fixed** — Fix JWK type direct not usable in configuration - **fixed** — Correct defects across the web frontend and suites - **fixed** — Fix data structure issues - **fixed** — Fix handlers to always log proper error - **fixed** — Fix incorrect middleware use in handlers - **fixed** — Use session regeneration more frequently in handlers - **fixed** — Treat empty basic parameter as malformed in handler - **fixed** — Fix incorrect multi writer order in logging - **fixed** — Fix missing record invocation in metrics - **fixed** — Include the error a session was not retrieved with in middlewares - **fixed** — Implement strict response validation in NTP - **fixed** — Fix client credentials at JWT missing sub in OIDC - **fixed** — Fix nominal entropy reduction in random - **fixed** — Fix stale errors and shutdown blocks in service ###### Bug Fixes * **api:** missing and misleading endpoints ([#12728](https://github.com/authelia/authelia/issues/12728)) ([b6de5c0](https://github.com/authelia/authelia/commit/b6de5c05a29f4ff27f92841d85db5a8866ef9073)) by @james-d-elliott * **authentication:** pooled client skip ([#12554](https://github.com/authelia/authelia/issues/12554)) ([7c34973](https://github.com/authelia/authelia/commit/7c3497394e76de013606eded16dcb8602a097684)) by @james-d-elliott * **authentication:** stale user database aliases ([#12755](https://github.com/authelia/authelia/issues/12755)) ([0c310f9](https://github.com/authelia/authelia/commit/0c310f96fb12ec166004e9b9e802da822cf1f577)) by @james-d-elliott * **authentication:** uncessary read lock ([#12620](https://github.com/authelia/authelia/issues/12620)) ([e0c4097](https://github.com/authelia/authelia/commit/e0c40973167318d421d36caa27b0521a5027ffd3)) by @james-d-elliott * **authorization:** deprecated wildcard consistency and did ([#12340](https://github.com/authelia/authelia/issues/12340)) ([aed96e8](https://github.com/authelia/authelia/commit/aed96e83f9dd148d7ad7a818d412922f7d6b0b1c)) by @james-d-elliott * **configuration:** add authelia.pam to scopes in schema ([#12705](https://github.com/authelia/authelia/issues/12705)) ([d769794](https://github.com/authelia/authelia/commit/d769794a50c4f7a43fdf32d2cc745812b917b263)) by @hendrik1120 * **configuration:** jwk type direct not usable ([#12756](https://github.com/authelia/authelia/issues/12756)) ([8942052](https://github.com/authelia/authelia/commit/894205202c3c8746f786246d2b16ff7fb8c77d31)) by @james-d-elliott * correct defects across the web frontend and the suites ([#12804](https://github.com/authelia/authelia/issues/12804)) ([daec9a3](https://github.com/authelia/authelia/commit/daec9a3737720a05ab731b1a29812308de02d9d3)) by @nightah * data structure issues ([#12704](https://github.com/authelia/authelia/issues/12704)) ([deadaf9](https://github.com/authelia/authelia/commit/deadaf92f64ae43501ddb8e1cf1060dfdb4fbe86)) by @james-d-elliott * **handlers:** always log proper error ([#12595](https://github.com/authelia/authelia/issues/12595)) ([8d57d0c](https://github.com/authelia/authelia/commit/8d57d0c386295376654337a706149f50b9402dca)) by @Crowley723 * **handlers:** incorrect middleware use ([#12339](https://github.com/authelia/authelia/issues/12339)) ([62b73a7](https://github.com/authelia/authelia/commit/62b73a73cb1337596f11b32ae84d3791f3ba143e)) by @james-d-elliott * **handlers:** use regeneration more frequently ([#12858](https://github.com/authelia/authelia/issues/12858)) ([bf517e6](https://github.com/authelia/authelia/commit/bf517e6bdadbcf4e7206532fcc99dfda21e9b569)) by @james-d-elliott * **handler:** treat empty basic parameter as malformed ([#12550](https://github.com/authelia/authelia/issues/12550)) ([2299998](https://github.com/authelia/authelia/commit/229999829ce1b256e78af5ec1c647b6a7d3671cb)) by @james-d-elliott * **logging:** incorrect multi writer order ([#12761](https://github.com/authelia/authelia/issues/12761)) ([ff9db2c](https://github.com/authelia/authelia/commit/ff9db2c02fd775de5bda60be305836ef335ef9ce)) by @james-d-elliott * **metrics:** missing record invocation ([#12267](https://github.com/authelia/authelia/issues/12267)) ([a9a5c65](https://github.com/authelia/authelia/commit/a9a5c65e2000a56dc7e262e7f39a85aa37a88ed3)) by @james-d-elliott * **middlewares:** include the error a session was not retrieved with ([#12868](https://github.com/authelia/authelia/issues/12868)) ([e77f3ac](https://github.com/authelia/authelia/commit/e77f3ac5e917d41468e75fac3ed7f5b1f935e771)) by @nightah * **ntp:** strict response validation ([#12551](https://github.com/authelia/authelia/issues/12551)) ([4c26b9d](https://github.com/authelia/authelia/commit/4c26b9dd786d1f0dff9ff3009b28359acbbc4486)) by @james-d-elliott * **oidc:** client credentials at jwt missing sub ([#12372](https://github.com/authelia/authelia/issues/12372)) ([1a1fdb2](https://github.com/a _[Truncated at 4000 characters — full notes: https://github.com/authelia/authelia/releases/tag/v4.39.21]_