github TecharoHQ/anubis v1.28.0-pre3
v1.28.0-pre3: Wuk Lamat

pre-release5 hours ago

Final smoke test prerelease before it ships properly, I swear.

  • Fix GHSA-5gwm-367w-7fgj, which allowed attackers that control the PTR records for their IP addresses to bypass Anubis via setting multiple PTR records pointing to various search engines.
  • Replace Thoth with GeoIP databases. GeoIP databases are configured in the geoip block.
  • Thoth functionality has been removed. THOTH_URL, THOTH_TOKEN, and THOTH_INSECURE are now deprecated environment variables that will log a warning upon startup.
  • ASN description values now use the Maxmind values instead of the values that Thoth returned. This may impact your fail2ban rules.
  • Native packages now create an anubis group and assign all Anubis instances permissions to /var/lib/anubis.
  • Fix the original-referer cookie not being affected by the COOKIE_PREFIX setting (#1977)
  • Default to the simplified explanation to avoid people misinterpreting words. USE_SIMPLIFIED_EXPLANATION is now deprecated.
  • Add Portuguese (Portugal) (pt-PT) localization.
  • Add documentation for the Headless Browser Detection extension and the Soteria challenge methods exclusive to BotStopper.
  • Add DYNAMIC_COOKIE_SUFFIX setting for toggling the dynamically generated cookie suffix #1992
  • Retry a missing challenge verification cookie once per client before reporting that cookies are disabled, allowing browsers affected by transient cookie loss during navigation to recover without creating an infinite challenge loop (#1916).

Small security fixes

As part of a continuous security posture, the following issues were identified and remediated:

  • Challenge validation for WASM based checks could fail open when users pass specifically crafted invalid input.
  • WASM challenges may only have four in-flight validations at once per process, the rest will wait in line.
  • Challenge solutions are now strictly bound to the issuing rule.
  • Path policies now prevent path traversal bypasses in some edge cases.
  • Duplicate header values are now consistently handled across edge cases.
  • Forwarded URI paths are evaluated separately from query strings.
  • Disallow clients from sending their JA4H value by using the Set header verb instead of Add.
  • Avoid a panic when parsing IPv6 answers from DNSBL hits in edge cases.
  • Avoid caching negative hits from DNSBL servers.
  • CDNs and middleware are now instructed to NOT cache Anubis challenge, completion, forward-auth, and error pages.
  • When a dynamic IP list updates to a list that has no entries, keep using the previous entry instead of deleting all IP list contents from memory.
  • Reject short HS512 secrets.
  • Restrict honeypot log permissions.
  • Handle malformed client IP addresses safely.
  • Fix concurrent TLS SNI handling in edge cases.
  • DNSBL hits are now cached correctly, even when the result is no entry found.

New Contributors

Full Changelog: v1.28.0-pre2...v1.28.0-pre3

Don't miss a new anubis release

NewReleases is sending notifications on new releases.