Skip to main content

SaaS Platform Services -- 1.2.135.2

Levo Team
Product & Engineering

Release period: v1.2.135.1 → v1.2.135.2

This release connects Levo to WSO2 API Gateway with a one-click push of endpoints, gives the Service Graph its own full-screen page, and adds AI-assisted triage from the vulnerability view. Security testing results are markedly more trustworthy: tests that could not run are reported as skipped rather than failed, several classes of false positives are gone, and injection tests once again reach the endpoints they target. DAST scans gain second-factor support, PDF reports get a redesign, and sign-in, SSO and administration are more reliable across identity providers.

Highlights​

  • WSO2 API Gateway integration — Connect a WSO2 account under Settings → Integrations, then push selected endpoints from any application straight into WSO2 as a new API.
  • Dedicated Service Graph page — The service graph moves out of the API Catalog to its own Inventory › Service Graph page, where it shows every service in the environment and fills the screen.
  • AI-assisted vulnerability triage — Copy an AI triage prompt from the vulnerability and application Security views, then record the verdict back to Levo with your confirmation.
  • More trustworthy test results — Tests that could not run are now Skipped with a stated reason instead of counting as failed checks, crashed checks are reported as errors rather than vulnerabilities, JWT replay false positives are eliminated, and injection tests no longer send malformed requests that servers rejected before the payload was evaluated.
  • Second-factor support for DAST scans — Web app scans can declare how a second factor is supplied, whether none, a static code or a relayed one-time code, and how long to wait for it. ShadowNet is also installable as a Python package for native, headed-browser scans on your own machines.
  • Redesigned PDF reports — Every PDF report template now follows the new Levo design system, with several data-display defects fixed along the way.

API Discovery & Cataloging​

New Features​

  • Service Graph page — The service graph has moved to its own Inventory › Service Graph page, showing every service in the environment at full width.
  • Source Type filter for applications — Filter the Applications tab by the source type of an application's endpoints.
  • Request bodies saved exactly as entered — Request bodies in endpoint parameters now keep their whitespace and key order, including when pasted, so endpoints that validate a signature over the raw payload accept them. A new Beautify option pretty-prints the body only when you ask.
  • Edit non-JSON request bodies — Form-urlencoded and other non-JSON bodies can now be edited in the catalog Parameters editor, and you can set the Content-Type when a body was captured without one or with the wrong one.
  • Clearer Kong imports — A Kong services file import now reports the endpoints it created and the application they went into, names any Kong routes that carry no method, and endpoints declared by a gateway show a KONG source badge alongside how else they were discovered.

Resolved Issues​

  • A form-urlencoded request body in the catalog Parameters editor is reported as invalid JSON with Save disabled, and bodies are reformatted just by opening them.
  • Form-urlencoded request bodies captured from traffic are stored as JSON instead of keeping their content type.
  • API endpoints that a service calls through a service-mesh sidecar appear as endpoints of the caller instead of the service that actually serves them.

API Security Testing​

New Features​

  • Readable test case logs — Request and response payloads no longer scroll sideways. Long header values collapse behind a character count you can expand, and any JWT can be decoded inline to see its header, payload and whether it is actually signed.

Resolved Issues​

  • Tests that cannot run because no baseline user is configured are counted as failed security checks, and run and suite failure counts include tests that never executed. They now report as Skipped with a clear reason.
  • Broken User Authentication tests report a passing result when the target did not respond or could not be authenticated against. Those runs are now reported as skipped with the reason stated.
  • Security checks that crash mid-run are shown as detected vulnerabilities. They are now reported as errors.
  • JWT attack checks report alg:none, embedded JWK or tampered claims as a signature bypass when the endpoint is not actually verifying the token — including routes that already ignore credentials, JSON catch-alls that return the same body unauthenticated, already-unsigned session tokens, and requests kept authorized by a sibling JWT or an alternate auth scheme such as an API key. Weak-HMAC secret recovery is unchanged.
  • OS command injection, local file inclusion, input validation, mass assignment and React2Shell checks send double-encoded request bodies that servers reject before the payload is evaluated, causing missed vulnerabilities and a misreported NoSQL finding. Local file inclusion tests fail outright on any endpoint with a request body.
  • The NoSQL Injection "Blind $where Operator Evaluation (Error Leak)" check misreports a generic JSON parse error from the target as a NoSQL driver error. Only genuine driver errors are now flagged, and the same encoding fix applies to SQL Injection body-parameter tests.
  • Security tests error out on responses they cannot read as text, such as binary, compressed, image, protobuf or unknown-charset bodies. These are now decoded on a best-effort basis, and UTF-16 and UTF-32 responses are read with the character set the server declared, so evidence inside them is still matched.
  • Server Version Disclosure inspects only normal responses, so a server or framework banner that leaks only on a 404 page is silently missed. Error-page responses are now inspected too, and each finding states which headers were seen on the endpoint's own response and which only on an unrouted path beneath it.
  • Findings for a web framework left in debug mode (CWE-489) are reported under Fuzzing instead of Security Misconfiguration, so they are missing from security-misconfiguration views and do not roll up against OWASP API8.
  • Long summaries on a test run's Skipped Summaries tab run over the link that opens the suite's logs instead of wrapping.

Web Application Scanning (DAST)​

New Features​

  • Second-factor authentication for scans — A DAST scan can now declare how a second factor is supplied, whether none, a static code or a relayed one-time code, along with how long the scan should wait for it.
  • ShadowNet as a Python package — ShadowNet is now installable from Levo's private package index with pip install shadownet, for native, headed-browser scans on your own machines.

AI Discovery​

Resolved Issues​

  • MCP tool import fails wholesale when a single tool has an unusually long description. The remaining tools now register, and long descriptions are stored in full.

Vulnerabilities & Findings​

New Features​

  • AI-assisted triage — Copy an AI triage prompt from the vulnerability and application Security views, and record the verdict back to Levo with your confirmation.

Resolved Issues​

  • The findings API returns an empty result set when a request fails or a date filter is invalid, and authentication failures return a bare 401. It now returns a descriptive error, accepts ISO-8601 timestamps, and states the reason for authentication failures.

Sensors & Deployment​

Resolved Issues​

  • The eBPF Sensor fails to start on Linux kernels older than 5.2, including Amazon Linux 2, Ubuntu 18.04 and RHEL 8, because one eBPF program exceeds the 4096-instruction limit those kernels enforce.
  • Tagger inactivity alerts scoped to an environment never fire, because the tagger reports a placeholder environment. Alerts are now routed by the environments the tagger actually serves, and webhook, Splunk and QRadar payloads for such a tagger carry an environmentNames list in place of the placeholder. Taggers deployed with an explicit environment are unchanged.
  • The Satellite inactive notification under Component Health either never fires when scoped to an environment or alerts every environment at once when unscoped, because a Satellite's environment cannot yet be determined. It has been withdrawn until Satellites can be routed correctly.

Integrations​

New Features​

  • WSO2 API Gateway — Connect a WSO2 account under Settings → Integrations and push selected endpoints from any application into WSO2 as a new API.

Resolved Issues​

  • Google SecOps (Chronicle) destinations configured through the integrations UI do not receive notification events, and events that are sent are rejected because of an incorrect envelope, event type and resource type. Delivery now works end to end, including in workspaces with no notification rules configured.
  • The Google SecOps integration page shows an incorrect Asia endpoint host and a delivery count that is always zero.

Reporting & Compliance​

New Features​

  • Redesigned PDF reports — All PDF report templates have been reworked to the new Levo design system with a consistent, modern look. No report data was removed.

Resolved Issues​

  • PDF reports omit some test results, drop table columns and misalign charts.

MCP Server​

New Features​

  • The Levo MCP server is now served on its own hostname, and the MCP setup page points to it.

Platform, Administration & Access​

New Features​

  • Owner and Admin roles reserved for the organization owner — Only the organization owner can now assign or remove the Owner and Admin roles. Admins keep full access to every other role, and roles now expose a tier so clients no longer infer privilege from a role's name.

Resolved Issues​

  • Loading environments fails for users with the Security Engineer role, and disabling role-based access control does not take effect immediately.
  • The admin Users page crashes on accounts with no email or name on file. They now show a placeholder avatar.
  • The admin Users list fails to load for organizations with very many users when filtered to All Users and Any Time.
  • The admin Users list shows the same authentication provider for every user instead of each user's real, current provider.
  • Sign-in, Satellite check-in and test runner connections intermittently time out for organizations using Keycloak authentication, because connections to the identity provider are not released after a rejected token refresh and a burst of failures exhausts the pool.
  • Signing up reports an identity conflict for organizations that do not use Single Sign-On.
  • Email verification, account lookup and enable or disable actions fail for an account held on a different identity provider from the caller, because the provider is inferred from the identifier's shape or the caller's provider rather than from the user's token or stored provider.
  • Migrating an organization between identity providers stops at the first failing user, a user whose organization was migrated without them cannot log in, and rollback fails after the migration has been run more than once. Each user now moves independently.

These fixes apply to Keycloak-backed organizations.

  • The Single Sign-On tab is hidden, so SSO cannot be configured.
  • SSO connections created from an identity provider's metadata URL fail every login after the provider has authenticated the user.
  • The Single Sign-On setup screen generates the ACS URL for the wrong domain.
  • Social login and SSO redirects use an unreachable internal address instead of a public hostname.
  • Choosing a specific social login provider can reuse an existing session from a different provider instead of authenticating against the chosen one.
  • Logging out of the app does not end the user's identity-provider session server-side.
  • The "please use a valid corporate email" warning is not shown after an SSO attempt with a personal email address.
  • The password reset link does not land on the app's reset page, and the reset cannot be completed there.