26.07 New Features and Changes

This is a regularly scheduled software release including new features and bug fixes.

Tip

Review the Upgrade Guide before performing any upgrade of pfSense software.

Netgate Nexus

This release contains new features exclusive to Netgate Nexus: CoreDNS, ThreatGate, and Snort 3.

CoreDNS

CoreDNS is an integrated component of Netgate Nexus which handles DNS-based tasks with extremely high performance. This component is based on the CoreDNS Project, but the functionality in Netgate Nexus is primarily focused on a new and exclusive CoreDNS plugin created by Netgate called rexdns.

ThreatGate

ThreatGate is an integrated component of Netgate Nexus which manages bulk lists of addresses and domains for use with firewall rules, aliases, and CoreDNS groups with high performance. ThreatGate collects addresses from internal and remote feeds and can block them entirely or allow administrators to build their own rules based on the content.

ThreatGate and CoreDNS were designed to integrate together and this allows them to quickly process and utilize huge lists of addresses even on small devices with low resources.

Snort 3

Snort version 3 is a new version of the popular open-source intrusion prevention system (IPS). It features a GUI redesigned from the ground-up, multi-threading support, and a faster rule syntax. Snort 3 is now available exclusively via the new Netgate Nexus controller GUI.

Security / Errata

pfSense Software

Upstream

  • Several security and errata fixes were merged from FreeBSD, including fixes for vulnerabilities discovered in WireGuard.

  • Several base system packages were updated to address various upstream security issues.

pfSense Plus

Changes in this version of pfSense Plus software.

Aliases / Tables

  • Fixed: Potential XSS via URL Table Ports Alias content #16945

  • Fixed: URL tables cannot import content from tgz file URLs #16964

Captive Portal

  • Fixed: Captive Portal authentication failures from usernames containing special characters or long strings can cause ambiguous or confusing log messages #16922

Configuration Backend

  • Changed: Improve handling of OpenSSL encryption passphrase #16958

DHCP (IPv4)

  • Added: Option to control Kea log level #16230

  • Changed: Kea attempts DNS Registration when Unbound is disabled #16865

  • Fixed: Daemon configuration manipulation via CR/LF in ISC DHCP settings #16900

  • Fixed: Potential XSS in DHCPv4 Pool Descriptions #16940

  • Added: Kea Custom Configuration JSON privilege #16960

  • Fixed: Daemon configuration manipulation via CR/LF in ISC DHCP numbered option settings #16962

DHCP (IPv6)

  • Fixed: Potential XSS in DHCPv6 Pool Descriptions #16941

DHCP Relay

  • Fixed: DHCP relay does not respect configured CARP VIP status #15017

DNS Resolver

  • Fixed: Unbound configuration may be generated with duplicate interface bindings #16906

Dashboard

  • Fixed: Potential XSS in Dynamic DNS widget display of Custom and RFC2136 entries #16944

  • Fixed: Potential Local File Include vulnerability via Dashboard widget sequence data #16947

Diagnostics

  • Fixed: Potential stored XSS in browser.php used by diag_edit.php #16918

  • Changed: Add device_key to filtered tags list for status output #16959

Dynamic DNS

  • Fixed: All-Inkl Dynamic DNS responses are not parsed correctly #16218

  • Changed: Encode Dynamic DNS credentials when passed as URL parameters #16905

Gateway Monitoring

  • Changed: Improve gateway status consistency #16707

Gateways

  • Changed: Improve default gateway detection when gateways share the same address #16816

  • Fixed: Static route not removed when enabling dpinger_dont_add_static_route while a gateway monitor IP address is set #16861

IPsec

  • Fixed: IPsec Keep Alive does not update the gateway status #15087

  • Fixed: Potential XSS via IPsec Phase 1 descriptions while editing Phase 2 entries #16942

IPv6 Router Advertisements (radvd/rtsold)

  • Fixed: IPv6 Track Interfaces ignores the Disabled Router Advertisements mode #16925

Interfaces

  • Fixed: VXLAN interfaces are configured with an incorrect MTU after re-saving their parent interface #16823

  • Added: Set IP Alias VIP as the Router Advertisement source #16914

Logging

  • Fixed: Potential XSS via inline Firewall Log rule descriptions #16923

OpenVPN

  • Fixed: Alert about missing MTU settings for OpenVPN DCO tunnels on every boot #16938

  • Fixed: RADIUS authentication fails when attribute contains an invalid ACL #16863

  • Fixed: Potential command execution via CR/LF in OpenVPN settings #16899

Operating System

  • Fixed: Kernel on armv7 can fail to parse loader configuration files #16746

  • Fixed: Loader menu does not display the logo properly #16726

PPP Interfaces

  • Fixed: Potential XSS in PPP instance Provider and Plan fields #16943

Package System

  • Fixed: Error updating repository metadata at boot with certain packages installed #16784

RRD Graphs

  • Fixed: Multiple updaterrd.sh processes #16927

Rules / NAT

  • Fixed: Cannot add Port Forward with an unassociated filter rule #15346

  • Fixed: Same port forward on multiple WANs can generate a PF error due to Pure NAT mode NAT reflection #16783

  • Changed: Retain a copy of the failed ruleset when a filter reload fails #16796

  • Fixed: Potential stored XSS via Firewall Schedules #16924

  • Fixed: Filter rules created as part of NAT rules can have an invalid protocol value #16954

SNMP

  • Fixed: Memory leak in libpfctl causes bsnmpd memory usage to grow over time #16456

  • Fixed: Daemon configuration manipulation via CR/LF in SNMP settings #16901

System Logs

  • Changed: Exclude nginx logs from system.log #16826

Traffic Graphs

  • Fixed: Potential XSS in Traffic Graphs Display option #16976

  • Fixed: Traffic Graphs display option “Description” does not utilize DHCP static mapping descriptions #16979

Traffic Shaper (ALTQ)

  • Fixed: Traffic Shaper Wizard duplicates all firewall rules when no shaping options are enabled #16866

Wake on LAN

  • Changed: “Wake All” functionality on services_wol.php should only use POST #16961

Web Interface

  • Fixed: Potential command execution via CR/LF in System Proxy settings #16898

Wireless

  • Fixed: Interfaces Status shows an invalid SSID value for Wi-Fi interfaces #16769