🚨 This major release upgrades to .NET 9 runtime and includes important security fixes. All cluster nodes must be upgraded together to maintain compatibility.
Key highlights in this release:
- Fixed Denial of Service vulnerability in rate limiting implementation with redesigned QPM options
- Fixed Cache Poisoning vulnerability through IP fragmentation attacks
- Fixed DNSSEC Downgrade vulnerability that could bypass validation
- Added Clustering feature to manage multiple DNS server instances from a single console
- Added Two-factor authentication (2FA) support with TOTP
- Added MISP Connector App to block malicious domains from MISP feeds
- Updated Advanced Blocking App with configurable TTL for blocked responses
- Enhanced Log Exporter App with EDNS logging support
- Improved support for comment entries in Allow/Block List URLs
- Multiple bug fixes for zone file parsing, session validation, and app configuration loading
Full release notes can be found at https://github.com/TechnitiumSoftware/DnsServer/blob/master/CHANGELOG.md