Zum Inhalt springen

Numa Release Notes

5 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Numa

Numa v0.24.1: Gehärtete DNSSEC-Validierung und Fixes

Numa v0.24.1 härtet die DNSSEC-Validierung (begrenzte Signaturprüfungen und NSEC3-Iterationen, keine Secure-Markierung bei RRsets ohne Signatur, gemeinsames Upstream-Query-Budget), korrigiert Forwarding-Regeln und Proxy-Accept-Loop und überarbeitet die README sowie den Docker-Build.

What's Changed

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Numa

Numa v0.24.0: DNS-Fixes, Rebinding-Lücke geschlossen, numa token

Numa v0.24.0 behebt die DNS-Auflösung in Linux-Heimnetzen (Suchdomains aus resolv.conf), UDP-Forwarding zu IPv6-Upstreams und eine DNS-Rebinding-Lücke in der Dashboard-API, wobei Loopback-Anfragen nun außer bei lokalem Host ein Token benötigen, und ergänzt numa token zum Auffinden des Dashboard-Tokens.

This release fixes DNS resolution on Linux home networks, UDP forwarding to IPv6 upstreams, and a DNS-rebinding hole in the dashboard API. It also adds numa token to help you find your dashboard token.

⚠️ Check before upgrading

Loopback requests now need the token unless Host is local. A page that DNS-rebinds its domain to 127.0.0.1 could previously read the query log and add overrides without a token. The loopback exemption now only applies when Host is localhost, *.localhost, an IP literal or a .numa name. (#420)

What to check: a same-host reverse proxy that passes the original Host through (Caddy and Traefik do by default) now gets a 401. Send the token upstream or rewrite Host to the upstream address. Opening the dashboard as http://<hostname>:5380 also asks for the token now.

🏠 Linux home networks

  • Search domains from resolv.conf (lan, fritz.box) forward to the system resolver instead of a hardcoded AWS VPC address that returned SERVFAIL everywhere else. Thanks @hb9eue (#414, #415)
  • Without systemd-resolved (Raspberry Pi OS, minimal Debian), the resolv.conf backup moves to /var/lib/numa so the unprivileged service can read it; existing backups migrate automatically (#418)

🌐 IPv6 upstreams

Plain-UDP IPv6 upstreams never worked, in forward or recursive mode, because the socket was always bound to 0.0.0.0. They do now. (#417)

📦 Smaller responses …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Numa

Numa v0.23.1: Zufällige Query-IDs und weniger DNSSEC-Fehlalarme

Numa v0.23.1 sendet im Forward-Modus zufällige Query-IDs gegen Cache-Poisoning, reduziert falsche DNSSEC-Fehler im Strict-Modus, behebt eine Regression des rekursiven Modus aus 0.23.0 und führt das Limit max_concurrent_resolutions (Standard 512) ein.

A patch release with a security fix for forward mode, fewer false DNSSEC failures in strict mode, and a fix for a 0.23.0 regression in recursive mode.

🔒 Security

  • Forward mode now sends upstreams a random query ID instead of passing the client's through, closing a one-packet cache-poisoning path (#397)
  • rustls bumped to 0.23.45 for RUSTSEC-2026-0285 (#396)

🧭 Resolution

  • Recursive mode resolves names like multi.surbl.org again, fixing a 0.23.0 regression where replies naming the root were rejected (#387, reported in #386)
  • A cached SERVFAIL now lives for seconds instead of min_ttl, so one upstream hiccup no longer blackholes a domain for a minute (#388, #376)
  • NXDOMAIN takes its TTL from the authority SOA, per RFC 2308 (#389)

🚦 New limit on concurrent lookups

max_concurrent_resolutions (default 512, 0 disables) caps cache misses running at once across UDP, TCP, DoT and DoH. Cached, local and coalesced answers are never counted. Over the cap, UDP is dropped silently and stream transports get SERVFAIL. (#364)

If you run numa for many clients, watch queries.refused and resolutions in /stats after upgrading.

🔏 DNSSEC

  • Strict mode no longer SERVFAILs zones such as isc.org and .ai: RSA keys under 2048 bits verify, RSASHA512 and ECDSA P-384 are supported, and unsupported algorithms are treated as Insecure (#390, #393)
  • Denial-of-existence proofs are authenticated (#393) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Numa

Numa v0.23.0: Ad-Blocking repariert, Resolver gegen Cache-Poisoning gehärtet

Numa v0.23.0 repariert das seit dem 1. August stillschweigend deaktivierte Ad-Blocking durch eine neue HaGeZi-Standardliste (wildcard/pro-onlydomains.txt) und härtet den rekursiven Resolver gemäß RFC 5452 gegen Cache-Poisoning.

Ad blocking was broken for everyone on the default config since 1 August. This release fixes it, and hardens the recursive resolver against cache poisoning.

🛡️ Ad blocking was silently off since 1 August

HaGeZi discontinued the hosts/ and domains/ formats on 2026-08-01. The compiled-in default pointed at one, and downloads never checked HTTP status — so a 145-byte error page parsed to zero domains and logged like a healthy load. (#336)

  • Default moved to wildcard/pro-onlydomains.txt; non-2xx and non-list bodies now fail loudly (#337)
  • /blocking/stats reports per-source health, so the dashboard shows which list is down instead of blanking (#339)
  • Each good list is cached to disk, so a restart during an upstream outage keeps blocking (#338)

If your numa.toml pins a HaGeZi hosts/ or domains/ URL, switch it to wildcard/ — the new default only applies if you never overrode it.

🔒 Recursive resolver hardening (RFC 5452)

  • Out-of-bailiwick referrals rejected — no more injecting NS, glue or DS for zones you don't own (#354, #355)
  • Random TXIDs from OsRng + reply validation on receipt, closing DNSpooq (CVE-2020-25684/85/86) and residual Kaminsky/SAD-DNS (#358, #359)
  • Bogon nameserver addresses refused, so referrals can't aim the resolver at your LAN (#356)
  • Per-query work budget and NS fan-out cap against NXNS / NRDelegation amplification (#357)
  • ANY answered with a minimal HINFO, RFC 8482 (#343)

📦 EDNS correctness …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Numa

Numa v0.22.0: Token für Dashboard und REST API, DNSSEC-Korrektur

Numa v0.22.0 verlangt für Dashboard und REST API von Nicht-Loopback-Clients ein Token (automatisch erzeugt beim ersten Start) und behebt, dass DNSSEC bei TXT-, HTTPS-, SVCB-, SRV-, NAPTR- und LOC-Records Antworten ohne Signaturprüfung als Secure meldete.

Highlights

🔐 Dashboard & API authentication

The dashboard and REST API now require a token for any non-loopback client — HTTP Bearer or Basic (native browser prompt). No config needed: a token is minted on first start, logged once, and persisted with 0600 perms, so no deployment is ever unauthenticated. Set your own via [server] api_token or NUMA_API_TOKEN; /health stays open for probes. The .numa reverse proxy forwards the real client IP, so proxied dashboard access gets the same check. (#315)

Upgrading with a dashboard already exposed beyond localhost? Your next visit will ask for credentials — the token is in the startup log (printed once) and in api_token inside your data directory (e.g. /var/lib/numa/, /usr/local/var/numa/). Use it as the password with any username, or set your own in numa.toml.

🔏 DNSSEC: record types that were never actually verified

With [dnssec] enabled = true, answers for types Numa stores as raw rdata — TXT, HTTPS, SVCB, SRV, NAPTR, LOC — were reported Secure without any signature verification: their rrsets never matched their RRSIGs, so validation silently skipped them. They are now signature-checked like everything else, including RFC 4034 canonical-form downcasing for SRV/NAPTR targets. DNSSEC validation is opt-in, so only [dnssec] users were affected. (#325, closes #324)

🔗 CNAME chase correctness …

Originalquelle(öffnet in neuem Tab)Problem melden