This release includes breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+3 more
ReleasePort's take
Moderate signalNetBird v0.72.3 introduces several client and management enhancements, including new Kubernetes commands, debug‑bundle masking, WebSocket relay fallback, IPv6 routing defaults, and request‑ID logging.
Why it matters: The deprecation gating added in this release stops sending the RemotePeers field after version v0.72.3; applications consuming that field must update before upgrading to avoid breaking changes.
Summary
AI summaryUpdates Client Improvements, Management Improvements, and Proxy Enhancements across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Added commands to discover and write Kubernetes configuration. Added commands to discover and write Kubernetes configuration. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Masked sensitive data during debug bundle creation. Masked sensitive data during debug bundle creation. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Added WebSocket relay fallback when QUIC datagrams exceed transport limits. Added WebSocket relay fallback when QUIC datagrams exceed transport limits. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Filtered DNS fallback upstreams matching NetBird server IPs to prevent loops. Filtered DNS fallback upstreams matching NetBird server IPs to prevent loops. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Preserved posture checks on configuration‑only sync updates. Preserved posture checks on configuration‑only sync updates. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Improved embedded client shutdown by canceling context before stopping the engine. Improved embedded client shutdown by canceling context before stopping the engine. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Added IPv6 default permit rules for exit node routes. Added IPv6 default permit rules for exit node routes. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Logged user agent information and returned request IDs. Logged user agent information and returned request IDs. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Feature | Low |
Added non‑blocking mapping updates to the proxy. Added non‑blocking mapping updates to the proxy. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Feature | Low |
Notified readiness for domains covered by static certificates in certificate handling. Notified readiness for domains covered by static certificates in certificate handling. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Performance | Low |
Improved support for atomic Linux distributions in install scripts and fixed Docker‑related issues. Improved support for atomic Linux distributions in install scripts and fixed Docker‑related issues. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
| Deprecation | High |
Added version gating to stop sending deprecated RemotePeers field. Added version gating to stop sending deprecated RemotePeers field. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Bugfix | Medium |
Fixed state manager crashes caused by concurrent iptables map access. Fixed state manager crashes caused by concurrent iptables map access. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Refactor | Low |
Switched proxy ID generation to use UUIDs. Switched proxy ID generation to use UUIDs. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
Full changelog
Release Notes for v0.72.3
What's New
Client Improvements
- Added commands to discover and write Kubernetes configuration.
experimental
https://github.com/netbirdio/netbird/pull/6260 - Masked sensitive data during debug bundle creation.
https://github.com/netbirdio/netbird/pull/6364 - Preserved user deselect-all route preferences across management syncs.
https://github.com/netbirdio/netbird/pull/6363 - Fixed state manager crashes caused by concurrent iptables map access.
https://github.com/netbirdio/netbird/pull/6345 - Added WebSocket relay fallback when QUIC datagrams exceed transport limits.
https://github.com/netbirdio/netbird/pull/6339 - Filtered DNS fallback upstreams matching NetBird server IPs to prevent loops.
https://github.com/netbirdio/netbird/pull/6183 - Preserved posture checks on configuration-only sync updates.
https://github.com/netbirdio/netbird/pull/6373 - Improved embedded client shutdown by canceling context before stopping the engine.
https://github.com/netbirdio/netbird/pull/6397
Management Improvements
- Added IPv6 default permit rules for exit node routes.
https://github.com/netbirdio/netbird/pull/6368 - Logged user agent information and returned request IDs.
https://github.com/netbirdio/netbird/pull/6380 - Added version gating to stop sending deprecated RemotePeers field.
https://github.com/netbirdio/netbird/pull/6371 - Fixed L4 service updates when no custom port is configured.
https://github.com/netbirdio/netbird/pull/6396
Proxy Enhancements
- Added non-blocking mapping updates.
https://github.com/netbirdio/netbird/pull/6369 - Improved certificate handling by notifying readiness for domains covered by static certificates.
https://github.com/netbirdio/netbird/pull/6389 - Switched proxy ID generation to UUIDs.
https://github.com/netbirdio/netbird/pull/6391
Infrastructure & Tooling
- Improved support for atomic Linux distributions in install scripts and fixed Docker-related issues in getting-started.sh.
https://github.com/netbirdio/netbird/pull/6139 - Updated the Go toolchain version in go.mod.
https://github.com/netbirdio/netbird/pull/6377
New Contributors
- @PizzaLovingNerd made their first contribution in https://github.com/netbirdio/netbird/pull/6139
- @bdolgov made their first contribution in https://github.com/netbirdio/netbird/pull/6389
Full Changelog: https://github.com/netbirdio/netbird/compare/v0.72.2...v0.72.3
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About netbird
Connect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.
Beta — feedback welcome: [email protected]