v9.4.0

nautechsystems/nautilus_traderv9.4.0Aug 17, 2026by jlongWang

AI Summary

SafeLine-CE introduces critical security vulnerability detection for Kafka Connect, .NET deserialization, and DedeCMS, alongside optimizations to detection logic and support for master-slave deployments and authentication session validity.

Key Highlights

  • Detection for Apache Kafka Connect arbitrary file read (CVE-2025-27817)
  • Detection for multiple .NET deserialization attack vectors
  • Detection for DedeCMS 5.7.2 remote code injection (CVE-2025-6335)
  • Master-slave deployment support with forwarding rule synchronization
  • Configuration for authentication session validity

New Features

  • Detection for Kafka Connect arbitrary file read vulnerability
  • Detection for .NET deserialization vectors (Json.NET, FastJson, XML, etc.)
  • Detection for DedeCMS remote code injection
  • Optimized detection logic for SQL injection, command injection, XSS, and CSRF
  • Optimized MongoDB NoSQL injection detection
  • Optimized Gzip decoding and HTTP protocol parsing
  • Automatic refresh for Attack Logs and Allowlist/Blocklist Detection Logs

Full Release Notes

### Added
- Added detection for the Apache Kafka Connect arbitrary file read vulnerability (CVE-2025-27817).
- Added detection for multiple .NET deserialization attack vectors, covering common exploitation methods involving Json.NET, FastJson, XML, NetDataContractSerializer, Xaml, BinaryFormatter, and more.
- Added detection for the DedeCMS 5.7.2 remote code injection vulnerability (CVE-2025-6335).

### Optimized

- Optimized detection logic for SQL injection, command injection, XSS, and CSRF.
- Optimized detection logic for Java deserialization, as well as Java, PHP, and ASP code injection.
- Optimized MongoDB NoSQL injection detection, covering request scenarios involving Query parameters, Forms, and JSON Keys.
- Optimized bot detection and server response detection logic.
- Optimized Gzip decoding and HTTP protocol parsing to improve detection capabilities for complex requests and compressed responses.
- Optimized the following enhanced rules:
    - Low-risk command execution
    - Requests accessing system files
    - Maccms 8.x remote code execution (CVE-2017-17733)
    - Dangerous Python functions
    - Java code injection
#### Master-Slave Deployment
- Added support for forwarding rule synchronization in master-slave deployment mode.

#### Authentication
- Added configuration for authentication session validity.
    - Available for both Simple Auth and Unified SSO:
        - Application → Auth → SIMPLE AUTH
        - Application → Auth → SSO

#### Other Improvements
- Added automatic refresh for Attack Logs and Allowlist/Blocklist Detection Logs.

### Fixes

- Fixed an issue where the Secret appeared empty after configuring GitHub as an authentication source.
- Fixed an encoding issue in Unified Authentication when the business URL contained multiple parameters, duplicate parameters, or already encoded parameters. The original business URL can now be restored correctly after authentication.
- Corrected the behavior of the Allow Rule “Today's Hits” link: the log entry is now only available when “Continue detecting and logging attack requests for allowlisted traffic” is enabled, preventing navigation to non-existent records.
- Fixed the AbortError: The user aborted a request error popup.
- Fixed compatibility issues with the Anti-bot Challenge slider on iPhone devices.
- Fixed an issue during the upgrade to v9.3.11 where backfilling a large number of historical rule logs could time out and cause safeline-mgt to fail to start.