tag:github.com,2008:https://github.com/AdguardTeam/AdGuardHome/releases
Release notes from AdGuardHome
2026-09-30T13:11:29Z
tag:github.com,2008:Repository/62712899/v1.0.0-b.1
2026-09-30T16:21:22Z
AdGuardHome v1.0.0-b.1
<p>Changes compared to the previous beta, v0.108.0-b.91. See <a href="https://github.com/AdguardTeam/AdGuardHome/tree/v1.0.0-b.1/CHANGELOG.md">CHANGELOG.md</a> for all changes.</p>
<h2>Full changelog</h2>
<h3>Security</h3>
<ul>
<li>Go version has been updated to prevent the possibility of exploiting the Go vulnerabilities fixed in <a href="https://groups.google.com/g/golang-announce/c/QiTRm-HGGtI" rel="nofollow">1.27.1</a>.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>Reading partially received TCP prefix.</p>
</li>
<li>
<p>A panic when updating AdGuard Home binary via the command line with <code>use_private_ptr_resolvers</code> set to true (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5505950311" data-permission-text="Title is private" data-url="https://github.com/AdguardTeam/AdGuardHome/issues/8613" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/8613/hovercard" href="https://github.com/AdguardTeam/AdGuardHome/issues/8613">#8613</a>).</p>
</li>
</ul>
<h3>Changed</h3>
<ul>
<li>The <code>beta</code> channel has been switched to the new UI and versioning scheme.</li>
</ul>
<h3>Removed</h3>
<ul>
<li>The support for macOS 13 Ventura, see <a href="https://go.dev/doc/go1.27#darwin" rel="nofollow">Go 1.27 release notes</a>.</li>
</ul>
EugeneOne1
tag:github.com,2008:Repository/62712899/v0.108.0-b.91
2026-09-28T15:52:24Z
AdGuardHome v0.108.0-b.91
<p>Changes compared to the previous beta, v0.108.0-b.90. See <a href="https://github.com/AdguardTeam/AdGuardHome/tree/v0.108.0-b.91/CHANGELOG.md">CHANGELOG.md</a> for all changes.</p>
<h2>Full changelog</h2>
<h3>Security</h3>
<ul>
<li>Go version has been updated to prevent the possibility of exploiting the Go vulnerabilities fixed in <a href="https://groups.google.com/g/golang-announce/c/QiTRm-HGGtI" rel="nofollow">1.26.8</a>.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p><code>log.enabled</code> set to <code>false</code> leaving the legacy logger enabled (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5160289429" data-permission-text="Title is private" data-url="https://github.com/AdguardTeam/AdGuardHome/issues/8565" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/8565/hovercard" href="https://github.com/AdguardTeam/AdGuardHome/issues/8565">#8565</a>).</p>
</li>
<li>
<p>DHCP server persisting uncommitted leases with zero expiry after <code>DHCPDISCOVER</code> messages (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5209068187" data-permission-text="Title is private" data-url="https://github.com/AdguardTeam/AdGuardHome/issues/8572" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/8572/hovercard" href="https://github.com/AdguardTeam/AdGuardHome/issues/8572">#8572</a>).</p>
</li>
<li>
<p>DNS64 treating unresolved <code>CNAME</code>/<code>DNAME</code> answers as the end of resolution chain (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2751063664" data-permission-text="Title is private" data-url="https://github.com/AdguardTeam/AdGuardHome/issues/7514" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/7514/hovercard" href="https://github.com/AdguardTeam/AdGuardHome/issues/7514">#7514</a>).</p>
</li>
</ul>
EugeneOne1
tag:github.com,2008:Repository/62712899/v0.107.79
2026-08-18T15:45:27Z
AdGuard Home v0.107.79
<p>It’s not always the big issues: sometimes what you need is a few fixes and tweaks to pump up the overall stability 🔩</p>
<h2>Full changelog</h2>
<p>See also the <a href="https://github.com/AdguardTeam/AdGuardHome/milestone/114?closed=1">v0.107.79 GitHub milestone</a>.</p>
<h3>Security</h3>
<ul>
<li>
<p>Go version has been updated to prevent the possibility of exploiting the Go vulnerabilities fixed in <a href="https://groups.google.com/g/golang-announce/c/94pEornpRlI" rel="nofollow">1.26.6</a>.</p>
</li>
<li>
<p>AdGuard Home is now more resistant to resource exhaustion attacks when using DNS-over-QUIC.</p>
<p>This is <a title="GHSA-w6v6-f44j-3rj2" href="https://github.com/AdguardTeam/dnsproxy/security/advisories/GHSA-w6v6-f44j-3rj2">GHSA-w6v6-f44j-3rj2</a>. We thank <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ATinyShoe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ATinyShoe">@ATinyShoe</a> for reporting this security issue.</p>
</li>
</ul>
<h3>Added</h3>
<ul>
<li>
<p>Bootstrap servers configuration now supports comments.</p>
</li>
<li>
<p>New property <code>"language"</code> in <code>POST /control/install/check_config</code> and <code>POST /control/install/configure</code> HTTP APIs.</p>
</li>
<li>
<p>The user is able to remove the static lease's hostname via the HTTP API.</p>
</li>
</ul>
<h3>Changed</h3>
<ul>
<li>The <code>edge</code> channel has been switched to the new UI and versioning scheme.</li>
</ul>
<h3>Deprecated</h3>
<ul>
<li><code>strict_sni_check</code> is now deprecated.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>DNS64 treating unresolved <code>CNAME</code>/<code>DNAME</code> answers as the end of resolution chain (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2751063664" data-permission-text="Title is private" data-url="https://github.com/AdguardTeam/AdGuardHome/issues/7514" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/7514/hovercard" href="https://github.com/AdguardTeam/AdGuardHome/issues/7514">#7514</a>).</p>
</li>
<li>
<p>Blocked requests without an EDNS(0) OPT record (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3773945128" data-permission-text="Title is private" data-url="https://github.com/AdguardTeam/AdGuardHome/issues/8183" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/8183/hovercard" href="https://github.com/AdguardTeam/AdGuardHome/issues/8183">#8183</a>).</p>
</li>
</ul>
adguard-bot
tag:github.com,2008:Repository/62712899/v0.108.0-b.90
2026-07-30T11:27:42Z
AdGuard Home v0.108.0-b.90
<p>Changes compared to the previous beta, v0.108.0-b.89. See <a href="https://github.com/AdguardTeam/AdGuardHome/tree/v0.108.0-b.90/CHANGELOG.md">CHANGELOG.md</a> for all changes.</p>
<h2>Acknowledgements</h2>
<p>A special thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ATinyShoe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ATinyShoe">@ATinyShoe</a> for reporting the vulnerability, our community moderators team, as well as to everyone who filed and inspected issues, added translations, and helped us test this release!</p>
<h2>Full changelog</h2>
<h3>Security</h3>
<ul>
<li>
<p>AdGuard Home is now more resistant to resource exhaustion attacks when using DNS-over-QUIC.</p>
<p>This is <a title="GHSA-w6v6-f44j-3rj2" href="https://github.com/AdguardTeam/dnsproxy/security/advisories/GHSA-w6v6-f44j-3rj2">GHSA-w6v6-f44j-3rj2</a>. We thank <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ATinyShoe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ATinyShoe">@ATinyShoe</a> for reporting this security issue.</p>
</li>
</ul>
<h3>Added</h3>
<ul>
<li>
<p>Bootstrap servers configuration now supports comments.</p>
</li>
<li>
<p>The user is able to remove the static lease's hostname via the HTTP API.</p>
</li>
</ul>
<h3>Changed</h3>
<ul>
<li>The <code>edge</code> channel has been switched to the new UI and versioning scheme.</li>
</ul>
<h3>Deprecated</h3>
<ul>
<li><code>strict_sni_check</code> is now deprecated.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Blocked requests without an EDNS(0) OPT record (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3773945128" data-permission-text="Title is private" data-url="https://github.com/AdguardTeam/AdGuardHome/issues/8183" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/8183/hovercard" href="https://github.com/AdguardTeam/AdGuardHome/issues/8183">#8183</a>).</li>
</ul>
adguard-bot
tag:github.com,2008:Repository/62712899/v0.108.0-b.89
2026-07-14T14:12:24Z
AdGuard Home v0.108.0-b.89
<p>Changes compared to the previous beta, v0.108.0-b.88. See <a href="https://github.com/AdguardTeam/AdGuardHome/tree/v0.108.0-b.89/CHANGELOG.md">CHANGELOG.md</a> for all changes.</p>
<h2>Acknowledgements</h2>
<p>A special thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nora-Qiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nora-Qiu">@Nora-Qiu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wallace0409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wallace0409">@wallace0409</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Evelynkaz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Evelynkaz">@Evelynkaz</a>, and <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/N0zoM1z0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/N0zoM1z0">@N0zoM1z0</a> for reporting the vulnerabilities, our community moderators team, as well as to everyone who filed and inspected issues, added translations, and helped us test this release!</p>
<h2>Full changelog</h2>
<h3>Security</h3>
<ul>
<li>
<p>AdGuard Home is now more resistant to JIGGLE attacks.</p>
<p>This is <a title="GHSA-p5f5-3p5g-rfjw" href="https://github.com/AdguardTeam/dnsproxy/security/advisories/GHSA-p5f5-3p5g-rfjw">GHSA-p5f5-3p5g-rfjw</a>. We thank <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nora-Qiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nora-Qiu">@Nora-Qiu</a> for reporting this security issue.</p>
</li>
<li>
<p>AdGuard Home now validates responses from DoH upstreams more strictly.</p>
<p>This is <a title="GHSA-4qjf-2hgm-92q6" href="https://github.com/AdguardTeam/dnsproxy/security/advisories/GHSA-4qjf-2hgm-92q6">GHSA-4qjf-2hgm-92q6</a>. We thank <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wallace0409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wallace0409">@wallace0409</a> for reporting this security issue.</p>
</li>
<li>
<p>QUIC connections are now protected from unbounded reads.</p>
<p>This is <a title="GHSA-qr92-rwvw-mhgh" href="https://github.com/AdguardTeam/dnsproxy/security/advisories/GHSA-qr92-rwvw-mhgh">GHSA-qr92-rwvw-mhgh</a> and <a title="GHSA-cccx-2r6r-m9r4" href="https://github.com/AdguardTeam/dnsproxy/security/advisories/GHSA-cccx-2r6r-m9r4">GHSA-cccx-2r6r-m9r4</a>. We thank <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wallace0409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wallace0409">@wallace0409</a> for reporting this security issue.</p>
</li>
<li>
<p>AdGuard Home now validates responses from DNSCrypt upstreams more strictly.</p>
</li>
<li>
<p>The H2C connection establishment via HTTP/1.1 request upgrade is no longer supported. See <a href="https://datatracker.ietf.org/doc/html/rfc9113" rel="nofollow">RFC 9113</a>.</p>
</li>
<li>
<p>Go version has been updated to prevent the possibility of exploiting the Go vulnerabilities fixed in <a href="https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc" rel="nofollow">1.26.5</a>.</p>
</li>
<li>
<p>The size of rulelists is limited. This is necessary to prevent a user's machine from becoming overloaded if the filter source misbehaves.</p>
<p>We thank Damir (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Evelynkaz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Evelynkaz">@Evelynkaz</a>) for reporting this security issue.</p>
</li>
<li>
<p>QUIC connections now observe timeouts more strictly.</p>
<p>This is <a title="GHSA-73vv-3434-p64c" href="https://github.com/AdguardTeam/AdGuardHome/security/advisories/GHSA-73vv-3434-p64c">GHSA-73vv-3434-p64c</a>. We thank <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/N0zoM1z0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/N0zoM1z0">@N0zoM1z0</a> for reporting this security issue.</p>
</li>
</ul>
<h3>Added</h3>
<ul>
<li>Improved updater logging to give users more insight into the problem with version updating (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4574339007" data-permission-text="Title is private" data-url="https://github.com/AdguardTeam/AdGuardHome/issues/8410" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/8410/hovercard" href="https://github.com/AdguardTeam/AdGuardHome/issues/8410">#8410</a>).</li>
</ul>
<h3>Changed</h3>
<ul>
<li>The interval of filter updates can now be set to any number of hours between <code>0</code> and <code>8760</code> (365 days) in the configuration file.</li>
</ul>
<h4>Configuration changes</h4>
<ul>
<li>The <code>filtering</code> object of the YAML configuration now includes a new property, <code>max_http_size</code>, which defines the maximum size of the HTTP request for rulelists. To disable the limitation, set a large size, such as <code>1 TB</code>.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>Validation of the <code>answer</code> field in DNS rewrite rules in case it is represented as CNAME.</p>
</li>
<li>
<p>Invalid AA flag in DNS responses (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3273181465" data-permission-text="Title is private" data-url="https://github.com/AdguardTeam/AdGuardHome/issues/7955" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/7955/hovercard" href="https://github.com/AdguardTeam/AdGuardHome/issues/7955">#7955</a>).</p>
</li>
<li>
<p>The parsing of the <code>ech</code> parameter in DNS rewrite rules for the HTTPS record type (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4015599198" data-permission-text="Title is private" data-url="https://github.com/AdguardTeam/AdGuardHome/issues/8276" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/8276/hovercard" href="https://github.com/AdguardTeam/AdGuardHome/issues/8276">#8276</a>).</p>
</li>
<li>
<p>Blocked services check on the Custom filtering rules page does not work properly without specifying of a client.</p>
</li>
</ul>
adguard-bot
tag:github.com,2008:Repository/62712899/v0.107.78
2026-07-13T15:12:58Z
AdGuard Home v0.107.78
<p>Security, security, security, security, security!</p>
<p>No, we do not have Steve Ballmer for CEO, but we took a page out of his playbook to draw attention to what we think is one of the most important aspects of developing AdGuard Home — security. This update is a good illustration of that: security-related changes take up over half of the changelog, and it’s not a small one.</p>
<p>We thank our awesome community members who helped us immensely by reporting some of the vulnerabilities, so that we could stay on top of our game and deliver timely fixes.</p>
<h2>Full changelog</h2>
<p>See also the <a href="https://github.com/AdguardTeam/AdGuardHome/milestone/113?closed=1">v0.107.78 GitHub milestone</a>.</p>
<h3>Security</h3>
<ul>
<li>
<p>AdGuard Home is now more resistant to JIGGLE attacks.</p>
<p>This is <a title="GHSA-p5f5-3p5g-rfjw" href="https://github.com/AdguardTeam/dnsproxy/security/advisories/GHSA-p5f5-3p5g-rfjw">GHSA-p5f5-3p5g-rfjw</a>. We thank <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nora-Qiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nora-Qiu">@Nora-Qiu</a> for reporting this security issue.</p>
</li>
<li>
<p>AdGuard Home now validates responses from DoH upstreams more strictly.</p>
<p>This is <a title="GHSA-4qjf-2hgm-92q6" href="https://github.com/AdguardTeam/dnsproxy/security/advisories/GHSA-4qjf-2hgm-92q6">GHSA-4qjf-2hgm-92q6</a>. We thank <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wallace0409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wallace0409">@wallace0409</a> for reporting this security issue.</p>
</li>
<li>
<p>QUIC connections are now protected from unbounded reads.</p>
<p>This is <a title="GHSA-qr92-rwvw-mhgh" href="https://github.com/AdguardTeam/dnsproxy/security/advisories/GHSA-qr92-rwvw-mhgh">GHSA-qr92-rwvw-mhgh</a> and <a title="GHSA-cccx-2r6r-m9r4" href="https://github.com/AdguardTeam/dnsproxy/security/advisories/GHSA-cccx-2r6r-m9r4">GHSA-cccx-2r6r-m9r4</a>. We thank <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wallace0409/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wallace0409">@wallace0409</a> for reporting this security issue.</p>
</li>
<li>
<p>AdGuard Home now validates responses from DNSCrypt upstreams more strictly.</p>
</li>
<li>
<p>The H2C connection establishment via HTTP/1.1 request upgrade is no longer supported. See <a href="https://datatracker.ietf.org/doc/html/rfc9113" rel="nofollow">RFC 9113</a>.</p>
</li>
<li>
<p>Go version has been updated to prevent the possibility of exploiting the Go vulnerabilities fixed in <a href="https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc" rel="nofollow">1.26.5</a>.</p>
</li>
<li>
<p>The size of rulelists is limited. This is necessary to prevent a user's machine from becoming overloaded if the filter source misbehaves.</p>
<p>We thank Damir (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Evelynkaz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Evelynkaz">@Evelynkaz</a>) for reporting this security issue.</p>
</li>
</ul>
<h3>Added</h3>
<ul>
<li>Improved updater logging to give users more insight into the problem with version updating (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4574339007" data-permission-text="Title is private" data-url="https://github.com/AdguardTeam/AdGuardHome/issues/8410" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/8410/hovercard" href="https://github.com/AdguardTeam/AdGuardHome/issues/8410">#8410</a>).</li>
</ul>
<h3>Changed</h3>
<ul>
<li>The interval of filter updates can now be set to any number of hours between <code>0</code> and <code>8760</code> (365 days) in the configuration file.</li>
</ul>
<h4>Configuration changes</h4>
<ul>
<li>The <code>filtering</code> object of the YAML configuration now includes a new property, <code>max_http_size</code>, which defines the maximum size of the HTTP request for rulelists. To disable the limitation, set a large size, such as <code>1 TB</code>.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>
<p>Invalid AA flag in DNS responses (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3273181465" data-permission-text="Title is private" data-url="https://github.com/AdguardTeam/AdGuardHome/issues/7955" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/7955/hovercard" href="https://github.com/AdguardTeam/AdGuardHome/issues/7955">#7955</a>).</p>
</li>
<li>
<p>The parsing of the <code>ech</code> parameter in DNS rewrite rules for the HTTPS record type (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4015599198" data-permission-text="Title is private" data-url="https://github.com/AdguardTeam/AdGuardHome/issues/8276" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/8276/hovercard" href="https://github.com/AdguardTeam/AdGuardHome/issues/8276">#8276</a>).</p>
</li>
<li>
<p>Blocked services check on the Custom filtering rules page does not work properly without specifying of a client.</p>
</li>
</ul>
adguard-bot
tag:github.com,2008:Repository/62712899/v0.108.0-b.88
2026-06-02T17:19:55Z
AdGuard Home v0.108.0-b.88
<p>Changes compared to the previous beta, v0.108.0-b.87. See <a href="https://github.com/AdguardTeam/AdGuardHome/tree/v0.108.0-b.88/CHANGELOG.md">CHANGELOG.md</a> for all changes.</p>
<h2>Acknowledgements</h2>
<p>A special thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djnnvx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djnnvx">@djnnvx</a> for reporting the vulnerability, our community moderators team, as well as to everyone who filed and inspected issues, added translations, and helped us test this release!</p>
<h2>Full changelog</h2>
<h3>Security</h3>
<ul>
<li>
<p>Authorization in GLiNET mode is no longer vulnerable to path traversal attacks.</p>
<p><strong>NOTE:</strong> This is <a title="CVE-2026-41448" data-hovercard-type="advisory" data-hovercard-url="/advisories/GHSA-599m-gqxc-4x5m/hovercard" href="https://github.com/advisories/GHSA-599m-gqxc-4x5m">CVE-2026-41448</a>. We thank <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djnnvx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djnnvx">@djnnvx</a> for reporting this security issue.</p>
</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Blocked services check on the Custom filtering rules page does not work properly without specifying of a client.</li>
</ul>
adguard-bot
tag:github.com,2008:Repository/62712899/v0.107.77
2026-06-02T12:52:16Z
AdGuard Home v0.107.77
<p>The quality of a product is not defined solely by code or developers’ technical prowess. A strong community—or the lack of one—can often make or break how successful a piece of software will be. We are very lucky to have such a devoted and passionate community around AdGuard Home. This update has once again demonstrated this, as we were able to quickly address a vulnerability reported by one of our community members.</p>
<h2>Acknowledgments</h2>
<p>A special thanks to <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djnnvx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djnnvx">@djnnvx</a> for reporting the vulnerability, our community moderators team and to everyone who filed and inspected issues, added translations, and helped us test this release!</p>
<h2>Full changelog</h2>
<p>See also the <a href="https://github.com/AdguardTeam/AdGuardHome/milestone/112?closed=1">v0.107.77 GitHub milestone</a>.</p>
<h3>Security</h3>
<ul>
<li>
<p>Authorization in GLiNET mode is no longer vulnerable to path traversal attacks.</p>
<p><strong>NOTE:</strong> This is <a title="CVE-2026-41448" data-hovercard-type="advisory" data-hovercard-url="/advisories/GHSA-599m-gqxc-4x5m/hovercard" href="https://github.com/advisories/GHSA-599m-gqxc-4x5m">CVE-2026-41448</a>. We thank <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/djnnvx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/djnnvx">@djnnvx</a> for reporting this security issue.</p>
</li>
</ul>
<h3>Added</h3>
<ul>
<li>New <code>reason</code> query parameter in <code>GET /control/querylog</code>. See <code>openapi/openapi.yaml</code> for the full description.</li>
</ul>
<h3>Deprecated</h3>
<ul>
<li>Query parameter <code>response_status</code> in <code>GET /control/querylog</code> is now deprecated. Use new <code>reason</code> query parameter instead.</li>
</ul>
adguard-bot
tag:github.com,2008:Repository/62712899/v0.108.0-b.87
2026-05-22T08:07:22Z
AdGuard Home v0.108.0-b.87
<p>Changes compared to the previous beta, v0.108.0-b.86. See <a href="https://github.com/AdguardTeam/AdGuardHome/tree/v0.108.0-b.87/CHANGELOG.md">CHANGELOG.md</a> for all changes.</p>
<h2>Full changelog</h2>
<h3>Changed</h3>
<ul>
<li>
<p>Duration values in YAML configuration file now support <code>d</code> (days) units and has been updated.</p>
<p><strong>NOTE:</strong> Any rollback to version below the <code>v0.107.76</code> should convert the values back to hours.</p>
</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>DNS caching with disabled DNSSEC (<a href="https://github.com/AdguardTeam/AdGuardHome/issues/8384" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/8384/hovercard">#8384</a>).</li>
</ul>
adguard-bot
tag:github.com,2008:Repository/62712899/v0.107.76
2026-05-21T18:26:30Z
AdGuard Home v0.107.76
<p>They say: don’t fix it if it’s not broken. But what if it is, in fact, broken? Like the cache we may have accidentally messed up during the last update? For such cases, there are hotfixes! Make sure to install the today’s update in order to fix the cache on your AdGuard Home.</p>
<h2>Acknowledgments</h2>
<p>A special thanks to our community moderators team and to everyone who filed and inspected issues, added translations, and helped us test this release!</p>
<h2>Full changelog</h2>
<p>See also the <a href="https://github.com/AdguardTeam/AdGuardHome/milestone/111?closed=1">v0.107.76 GitHub milestone</a>.</p>
<h3>Changed</h3>
<ul>
<li>
<p>Duration values in YAML configuration file now support <code>d</code> (days) units and has been updated.</p>
<p><strong>NOTE:</strong> Any rollback to version below the <code>v0.107.76</code> should convert the values back to hours.</p>
</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>DNS caching with disabled DNSSEC (<a href="https://github.com/AdguardTeam/AdGuardHome/issues/8384" data-hovercard-type="issue" data-hovercard-url="/AdguardTeam/AdGuardHome/issues/8384/hovercard">#8384</a>).</li>
</ul>
adguard-bot