Features Added
- Scheduled the Glamsterdam (Gloas) upgrade on Sepolia for epoch 353024 (October 6, 2026 13:53:36 UTC). #1240
- Signing support for the upcoming Glamsterdam (GLOAS / ePBS) fork, matching remote-signing-api v1.4.0. #1192
- Unstable CLI options (names beginning
--X) are now listed byweb3signer -X(or--Xhelp), grouped by the command they belong to.web3signer eth2 -Xlists only theeth2unstable options. #1228 - Azure Key Vault connections are now cached per credential/vault set instead of rebuilt on every key load, reducing bulk-load time. #1222
- Vert.x is upgraded to 5.2.0 and web3j to 6.0.0, together with the other dependencies and build plugins. #1231
Bugs Fixed
- Azure Key Vault SECP256K1 signing now uses one official Azure SDK
CryptographyClientper key instead of REST workaround. #1222 - Netty is upgraded to
4.2.17.Finalto prevent io_uring read stalls on reused connections.#1222 eth_signTransactionfor EIP-4844 transactions now returns the canonical signed transaction (0x03 || rlp([...])) instead of wrapping it in a blob network wrapper with empty sidecar lists. #1231- HTTP API errors (Key Manager, signing, reload, unknown paths) now return
application/jsonwith a{"code": <status>, "message": "..."}body instead of plain text or HTML. A host allow-list rejection on the eth1 JSON-RPC endpoint (POST /) returns that body too, instead of an id-less-32603JSON-RPC envelope. eth1 JSON-RPC responses now sendContent-Type: application/jsoninstead of the misspelledContentheader. #1235
Breaking Changes
- The
http_vertx_worker_pool_rejected_totalmetric is no longer exported, because Vert.x 5 does not report rejected worker tasks separately (they only occur once a pool has shut down). The bundled Grafana dashboard now charts worker queue delay instead. #1231 POST /reloadresponses now use the shared{"code": <status>, "message": "..."}body:202returns"code": 202instead of"status": "accepted", and409returns"code": 409instead of"status": "error".GET /reloadis unchanged. #1235
CI/Build Enhancements
- Azure Key Vault acceptance tests now run against local Azure emulator instance instead of live Azure.
- OWASP dependency-check runs nightly again, scanning only the dependencies shipped in the distribution (
runtimeClasspath) and publishing findings to GitHub code scanning. The NVD database is cached between runs and rebuilt weekly; the run fails if the NVD data is more than 48 hours old. Stale suppressions were removed and current false positives documented. #1237
Security
- Docker base images re-pinned to their current multi-platform index digests. #1230
- Default image ships
ubuntu:26.04+ Eclipse Temurin JRE 25.0.4; distroless image ships Java 25.0.4 ongcr.io/distroless/java25-debian13:nonroot. #1230
Downloads
Binaries
| Binary | Checksum |
|---|---|
| web3signer.tar.gz | Checksum |
| web3signer.zip | Checksum |
Docker
Default image (Ubuntu + Eclipse Temurin JRE 25):
docker pull consensys/web3signer:26.9.0-RC1
Hardened image (Google Distroless, read-only-filesystem compatible):
docker pull consensys/web3signer:26.9.0-RC1-distroless
Verify
Binaries, with the GitHub CLI:
# the file is the one published with this release
gh release verify-asset 26.9.0-RC1 web3signer-26.9.0-RC1.tar.gz --repo Consensys-Incorporated/web3signer
# the file was built by this repository's CI workflow
gh attestation verify web3signer-26.9.0-RC1.tar.gz --repo Consensys-Incorporated/web3signerDocker images: see Verifying image signatures and attestations.
Full Changelog: 26.7.0...26.9.0-RC1