v2.0.0-rc10
mukul975/cve-mcp-serverv2.0.0-rc10Dec 22, 2025by qdm12
AI Summary
This release candidate introduces performance improvements for DNS over TLS, new configuration options for health checks and rebinding protection, and fixes for public TLD detection. It also includes breaking changes to the nameserver Go API.
Key Highlights
- DNS over TLS now uses a connection pool for reusing TCP connections
- New configuration options: HEALTH_SERVER_ADDRESS and REBINDING_PROTECTION_EXEMPT_HOSTNAMES
- Breaking changes in pkg/nameserver GetDNSServers return types
- Fixes for local DNS middleware logging and public TLD detection
Breaking Changes
- pkg/nameserver.GetDNSServers returns []netip.Addr instead of []netip.AddrPort
- pkg/nameserver.GetDNSServers returns an error instead of just values
- pkg/nameserver.GetDNSServers does not return localhost IPs if no nameserver is found
New Features
- DNS over TLS connection pooling
- HEALTH_SERVER_ADDRESS configuration option
- REBINDING_PROTECTION_EXEMPT_HOSTNAMES configuration option
- Middleware logging for blocked elements with reasons
- Grafana dashboard update to schema version 3
Full Release Notes
## Features - DNS over TLS now uses a pool of connections to re-use TCP connections when possible (#150) - `HEALTH_SERVER_ADDRESS` option, defaulting to `127.0.0.1:9999` - by default log i/o timeout errors are logged at debug level because these are fairly common - `REBINDING_PROTECTION_EXEMPT_HOSTNAMES` option - `pkg/middlewares/filter`: log blocked elements with a reason ## Fixes - `internal/local`: "site" and "network" TLDs are public, not local - `pkg/middlewares/localdns`: - do not log request twice on errors - do not debug log NXDOMAIN coded responses since these happen often especially with search domains - `internal/support/ipv6`: handle Windows error message - Grafana dashboard plain DNS section updated ## Go API breaking changes - `pkg/nameserver`: `GetDNSServers` - does not return localhost IPs if no nameserver is found - returns an eventual error - returns []netip.Addr instead of []netip.AddrPort since it can only be an ip address without port ## Maintenance - Grafana JSON dashboard upgraded to newer schema version 3 - Fix documentation URLs and CI links check - bump markdownlint from v11 to v21