← Back to all sparks
A

AdGuard Home

INFRA · APIS
Velocity5.0

Self-hosted network-wide ad and tracker blocking DNS server

AdGuard Home is spending most of its release capacity on DNS protocol vulnerabilities.

dns-filteringencrypted-dnssecurity-advisoriesdual-branchself-hostedui-rewrite
Current state
Two trains run in parallel: the 0.107.x stable line and a long-running 0.108.0 beta series now at b.90. Security dominates both — one stable release opened by admitting security changes take up over half its changelog. The reported issues cluster in the encrypted-DNS stack: JIGGLE attacks, loose validation of DoH upstream responses, unbounded reads on QUIC connections, DNS-over-QUIC resource exhaustion, and a path traversal in GLiNET-mode authorization. Feature work in the window is minor: comments in bootstrap server configuration, removing a static lease hostname via the HTTP API, day units in YAML durations.
Where it's heading
The 0.108 beta has been running long enough that its interesting signal is the edge channel switching to the new UI and versioning scheme — the rewrite is reaching users before the beta closes. Meanwhile the security cadence is community-driven: nearly every fix credits an external reporter, and fixes land in a beta and its stable counterpart within days or the same day. That is a project whose attack surface is its protocol implementations, and whose defence is a fast disclosure-to-patch loop rather than architectural change.
Prediction
Expect the encrypted-DNS transports to keep generating reports and same-week patches on both branches, and the new UI to widen from the edge channel toward beta as 0.108 approaches release.

Recent moves

  1. 5d ago

    AdGuard Home v0.108.0-b.90

    A beta hardening DNS-over-QUIC against resource exhaustion, adding comments in bootstrap server configuration and hostname removal via the HTTP API. The notable line is operational rather than security: the edge channel switched to the new UI and versioning scheme, putting the rewrite in front of users ahead of the 0.108 release.

    View source ↗
  2. 20d ago

    AdGuard Home v0.108.0-b.89

    A beta consolidating three separately reported vulnerabilities — JIGGLE resistance, stricter validation of DoH upstream responses, and protection against unbounded reads on QUIC connections. All three sit in the encrypted-DNS transports, which is where this project's risk concentrates.

    View source ↗
  3. 21d ago

    AdGuard Home v0.107.78

    The stable counterpart to the same advisory batch, shipped a day earlier and explicitly framed by the team as a security-first release. It is the clearest statement of where AdGuard Home's engineering attention sits right now.

    View source ↗
  4. 2mo ago

    AdGuard Home v0.108.0-b.88

    The beta twin of the same-day stable release fixing a path traversal in GLiNET-mode authorization, plus one filtering-page fix. Same content as v0.107.77 — read that entry for the substance.

    View source ↗
  5. 2mo ago

    AdGuard Home v0.107.77

    A stable release fixing a path traversal vulnerability in GLiNET-mode authorization, reported by a community member and patched quickly on both branches. Demonstrates the disclosure-to-patch loop this project runs on.

    View source ↗
  6. 2mo ago

    AdGuard Home v0.108.0-b.87

    A small beta adding day units to YAML duration values and fixing DNS caching with DNSSEC disabled. Note the rollback caveat: downgrading below v0.107.76 requires converting durations back to hours.

    View source ↗