app/v2.9.2

parruda/swarmapp/v2.9.2May 23, 2026by github-actions[bot]

AI Summary

This release addresses critical security vulnerabilities by implementing experimental Gecko obfuscation and fixing ACL bypass issues. It also resolves stability problems related to UDP handling and server memory usage.

Key Highlights

  • Added experimental Gecko obfuscation for QUIC packets
  • Fixed UDP packet ACL bypass vulnerability
  • Fixed server OOM caused by incomplete HTTP requests
  • Fixed ACL bypass via trailing dots in domain names
  • Fixed SOCKS5 UDP outbound destination handling

New Features

  • Gecko obfuscation layer
  • ACL bypass security patches
  • DoH resolver prefix detection fix
  • Outbound rule validation for ports
  • Performance improvements

Full Release Notes

> This release contains important security fixes and we strongly encourage everyone to upgrade.

- Added [Gecko obfuscation](https://hysteria.network/docs/advanced/Full-Server-Config/#__tabbed_2_2): a new experimental obfuscation layer that fragments QUIC handshake packets
- Fixed a security issue where UDP packets could bypass ACL
- Fixed a potential server OOM caused by incomplete or oversized HTTP requests during sniff
- Fixed an ACL bypass via trailing dots in domain names (e.g. `example.com.`)
- Fixed incorrect destination handling in the SOCKS5 UDP outbound
- Fixed `https://` prefix detection in the DoH resolver
- Outbound rules now reject invalid port values
- Minor performance improvements

---

> 此版本包含重要安全修复,强烈建议更新

- 新增 [Gecko](https://hysteria.network/docs/advanced/Full-Server-Config/#__tabbed_2_2):一种实验性的新混淆实现,会对 QUIC 握手包进行分片处理
- 修复了 UDP 包可绕过 ACL 的安全问题
- 修复了启用 sniff 时,不完整或超大 HTTP 请求可能导致服务端 OOM 的问题
- 修复了通过在域名末尾添加点(如 `example.com.`)绕过 ACL 的问题
- 修复了 SOCKS5 UDP 出站中目标地址处理错误的问题
- 修复了 DoH 解析器对 `https://` 前缀的判断错误
- outbound 规则现在会拒绝无效端口号
- 小幅性能改进