ChangeLog

Version 1.3.2 (2026-10-01)

  • Update the vendored ModSecurity library from 3.0.15 to 3.0.17. This addresses the following upstream security advisories, several of which are WAF bypasses:
    • CVE-2026-73856: response body inspection bypass with a mixed-case Content-Type value.
    • CVE-2026-73857: uninitialized pointer dereference in the XML request body processor when SecParseXmlIntoArgs is enabled.
    • CVE-2026-61812: t:htmlEntityDecode only decoded a handful of named HTML entities.
    • CVE-2026-61813: weak TLS host verification for remote rule downloads.
    • CVE-2026-52747: invalid handling of \r and \n in the multipart/form-data request body parser.
    • GHSA-5pww-8rfg-9crf: multipart filename inspection bypass via the RFC 2231 filename* parameter and duplicated filename parameters.
    • GHSA-5m93-4h75-3p2w: @rx/@rxGlobal null pointer dereference on an invalid pattern, and PCRE2 match-limit errors treated as no-match.
    • GHSA-qrch-pjfr-9g47: t:removeComments did not strip adjacent comments.
    • GHSA-4j47-8qcr-jf59: t:base64DecodeExt did not handle the URL-safe alphabet.
  • Add arm64 packages for the platforms where Varnish Enterprise is available on arm64.
  • Drop packages for Debian 11 (Bullseye), which is end of life.

Version 1.3.1 (2026-07-03)

  • Fix the XML request body processor leaking libxml2 parser errors for malformed XML to the worker’s standard error, where each line was echoed to the log by the manager as Child (NNN) said .... Attacker-controlled malformed bodies could thus flood the host logs.

Version 1.3.0 (2026-06-30)

  • Add .detection_mode() to query the WAF engine’s effective state (On/DetectionOnly/Off) for the current transaction from VCL.
  • Add .log_matches() to write non-disruptive rule matches to the VSL under the WAF tag with a MATCH: prefix, for observability while running in DetectionOnly or while tuning CRS anomaly scoring. Wired to the waf-log-matches request header in the bundled waf.vcl.

Version 1.2.3 (2026-05-26)

  • Fix a SecLang parser bug where certain rule contents caused stray writes to the worker’s standard output, which could cause the worker to be silently reaped by the manager.

Version 1.2.2 (2026-05-13)

  • Update the vendored ModSecurity library to 3.0.15. This addresses CVE-2026-42268 (integer underflow in the verify* operators), along with a number of other upstream stability fixes.
  • Drop the local HexDecode patch shipped in 1.2.1 in favor of the equivalent upstream fix for CVE-2026-30923 in ModSecurity 3.0.15.
  • Add packaging for Ubuntu 26.04 (Resolute Raccoon).

Version 1.2.1 (2026-03-23)

  • Fix a buffer overflow in the HexDecode transformation, discovered independently and later assigned CVE-2026-30923 upstream.
  • Add packaging for Debian 13 (Trixie)

Version 1.2.0 (2026-03-19)

  • Allow the init object to be NULL: methods now fail gracefully with VRT_fail instead of asserting when called on a NULL object.

Version 6.0.12r6 (2024-01-31)

  • Update the vendored ModSecurity library to address vulnerability CVE-2024-1019.

Version 6.0.9r7 (2022-05-20)

  • Add function to skip rules by id or tag.

Version 6.0.8r4 (2021-08-26)

  • Update the OWASP CRS install helper script to install a newer version of OWASP CRS by default (CVE-2021-35368). This script is for convenience. The user is responsible for managing the rule set.

Version 6.0.8r2 (2021-06-02)

  • Fix a crash caused by calling .check_req() with a NULL string.

Version 6.0.6r1 (2019-02-19)

Version 6.0.5r1 (2019-10-21)

  • Initial Release.

®Varnish Software, Wallingatan 12, 111 60 Stockholm, Organization nr. 556805-6203