Final smoke test prerelease before it ships properly, I swear.
- Fix GHSA-5gwm-367w-7fgj, which allowed attackers that control the PTR records for their IP addresses to bypass Anubis via setting multiple PTR records pointing to various search engines.
- Replace Thoth with GeoIP databases. GeoIP databases are configured in the
geoipblock. - Thoth functionality has been removed.
THOTH_URL,THOTH_TOKEN, andTHOTH_INSECUREare now deprecated environment variables that will log a warning upon startup. - ASN description values now use the Maxmind values instead of the values that Thoth returned. This may impact your fail2ban rules.
- Native packages now create an
anubisgroup and assign all Anubis instances permissions to/var/lib/anubis. - Fix the original-referer cookie not being affected by the
COOKIE_PREFIXsetting (#1977) - Default to the simplified explanation to avoid people misinterpreting words.
USE_SIMPLIFIED_EXPLANATIONis now deprecated. - Add Portuguese (Portugal) (
pt-PT) localization. - Add documentation for the Headless Browser Detection extension and the Soteria challenge methods exclusive to BotStopper.
- Add DYNAMIC_COOKIE_SUFFIX setting for toggling the dynamically generated cookie suffix #1992
- Retry a missing challenge verification cookie once per client before reporting that cookies are disabled, allowing browsers affected by transient cookie loss during navigation to recover without creating an infinite challenge loop (#1916).
Small security fixes
As part of a continuous security posture, the following issues were identified and remediated:
- Challenge validation for WASM based checks could fail open when users pass specifically crafted invalid input.
- WASM challenges may only have four in-flight validations at once per process, the rest will wait in line.
- Challenge solutions are now strictly bound to the issuing rule.
- Path policies now prevent path traversal bypasses in some edge cases.
- Duplicate header values are now consistently handled across edge cases.
- Forwarded URI paths are evaluated separately from query strings.
- Disallow clients from sending their JA4H value by using the Set header verb instead of Add.
- Avoid a panic when parsing IPv6 answers from DNSBL hits in edge cases.
- Avoid caching negative hits from DNSBL servers.
- CDNs and middleware are now instructed to NOT cache Anubis challenge, completion, forward-auth, and error pages.
- When a dynamic IP list updates to a list that has no entries, keep using the previous entry instead of deleting all IP list contents from memory.
- Reject short HS512 secrets.
- Restrict honeypot log permissions.
- Handle malformed client IP addresses safely.
- Fix concurrent TLS SNI handling in edge cases.
- DNSBL hits are now cached correctly, even when the result is no entry found.
New Contributors
- @bibliotechy made their first contribution in #1975
- @MeGaurav4 made their first contribution in #1984
- @SniperCZE made their first contribution in #1965
- @lbellomo made their first contribution in #1964
- @GustavFredrikson made their first contribution in #2004
- @Blackspirits made their first contribution in #1993
Full Changelog: v1.28.0-pre2...v1.28.0-pre3