v0.74.7
stalwartlabs/stalwartv0.74.7Jul 17, 2026by lixmal
AI Summary
This release focuses on security hardening and performance improvements for the NetBird client and relay. It introduces concurrent QUIC handling to prevent handshake head-of-line blocking and addresses potential security vulnerabilities by sanitizing user inputs and SSH configurations.
Key Highlights
- Handle QUIC connections concurrently to prevent handshake head-of-line blocking
- Reject leading hyphen in getent input to prevent flag injection
- Sanitize peer FQDN/hostname in generated SSH config
- Evaluate IP fragments against firewall ACLs
- Bind netstack SOCKS5 proxy to 127.0.0.1 by default
Full Release Notes
## What's Changed * [relay] Handle QUIC connections concurrently to prevent handshake head-of-line blocking by @lixmal in https://github.com/netbirdio/netbird/pull/6784 * [client] Reject leading hyphen in getent input to prevent flag injection by @lixmal in https://github.com/netbirdio/netbird/pull/6787 * [client] Sanitize peer FQDN/hostname in generated SSH config by @riccardomanfrin in https://github.com/netbirdio/netbird/pull/6805 * [client] Disable gVisor TCP RACK loss detection on Windows by @lixmal in https://github.com/netbirdio/netbird/pull/6808 * [client] Rename isValidAccessToken to reflect audience-only check by @riccardomanfrin in https://github.com/netbirdio/netbird/pull/6806 * [client] Bind netstack SOCKS5 proxy to 127.0.0.1 by default by @riccardomanfrin in https://github.com/netbirdio/netbird/pull/6812 * [client] Evaluate IP fragments against firewall ACLs by @lixmal in https://github.com/netbirdio/netbird/pull/6781 **Full Changelog**: https://github.com/netbirdio/netbird/compare/v0.74.6...v0.74.7