v9.3.9

TEN-framework/ten-frameworkv9.3.9Jun 17, 2026by jlongWang

AI Summary

This update focuses on security hardening to address CVE-2026-49975 and improves the Threat Intelligence Sharing program. It also includes stability fixes for certificate synchronization, access logs, and configuration management.

Key Highlights

  • Security hardening via Nginx component upgrade for CVE-2026-49975
  • Fixed static file path handling security edge case
  • Upgraded Threat Intelligence Sharing program
  • Optimized certificate sync to reduce unnecessary Nginx reloads
  • Fixed access log switching and certificate application issues

New Features

  • Upgraded Threat Intelligence Sharing
  • Updated IP geo location database

Full Release Notes

## Release Notes

This release focuses on security hardening, an upgrade to the Threat Intelligence Sharing program, and several stability and user experience fixes. Community Edition users are advised to update promptly.

  ### Security Hardening

  - Upgraded Nginx-related components to mitigate the potential security risk of CVE-2026-49975 and improve the runtime security of the protection service.
  - Fixed an edge case in static file path handling related to Auth,improving security when abnormal paths are accessed.

  ### Improvements

  - Upgraded Threat Intelligence Sharing.
  - Updated the IP geo location database.

  ### Bug Fixes

  - Fixed an issue where the application access log could automatically switch back to the real time log after refresh or polling while viewing the History log.
  - Fixed an issue where a failed Free Cert application or renewal could trigger an abnormal full rebuild of application configuration.
  - Optimized certificate synchronization and configuration reload logic to reduce unnecessary Nginx/MGT reloads when certificate content has not changed.