This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 23d
SIEM & Threat Detection
✓ No known CVEs patched
This release patches 3 known CVEs
Topics
cloud-security
compliance
configuration-assessement
container-security
security
file-integrity-monitoring
+12 more
incident-response
log-analysis
malware-detection
pci-dss
security-audit
security-automation
security-hardening
security-tools
siem
vulnerability-detection
wazuh
xdr
Affected surfaces
auth
rbac
deps
Summary
AI summaryUpdates Manager, Agent, and Other across a mixed release.
Full changelog
Manager
Removed
- Removed unused SSL/TLS transport option from cluster. (#35648)
Fixed
- Improved message decompression handling in remoted. (#35773)
- Improved agent name validation to reject names starting with dot. (#35833)
- Fixed segfault in vulnerability scanner module shutdown when disabled. (#36011)
- Fixed string buffer handling in version comparison function. (#36059)
- Improved cluster file synchronization security. (#36060)
- Improved cluster file synchronization error handling on invalid task identifiers. (#36129)
- Improved cluster merged file parameter validation to prevent directory escape. (#36204)
- Improved
tmp_filepath validation in cluster DAPI. (#36246) - Improved cluster non-merged file path validation during worker file processing. (#36296)
- Improved cluster node name format validation in the hello handler. (#36460)
- Fixed missing
agent.host.ipin inventory documents when agent IP is empty. (#35475) - Fixed stale agent
syncedstatus after hot reload on cluster worker nodes. (#6726)
Agent
Fixed
- Fixed agent registration not running on reinstall after
apt-get remove. (#35727) - Fixed MS-Graph integration handling for relationships containing
/. (#35431) - Fixed macOS syscollector to skip package receipts whose payload is no longer installed. (#35380)
- Fixed missing eBPF create, modify and delete events on Ubuntu 24/26 and improved FIM whodata healthcheck. (#35838)
- Hardened FIM database path lookups by migrating to parameterized SQL queries. (#36399)
RESTful API
Fixed
- Escaped control characters in API usernames in access logs. (#35866)
- Added input validation in cluster result handling and authentication. (#35757)
- Fixed current user resolution in the
update-userendpoint to enforce admin protection. (#35442)
Ruleset
Fixed
- Updated rootcheck trojan signatures to avoid false positives on modern distributions (Debian 13, Ubuntu 26, Arch Linux). (#35927)
Other
Changed
- Updated
cryptography,urllib3andpython-multipartPython dependencies. (#35982) - Updated eBPF libraries:
libbpfto 1.7.0 andbpftoolto 7.7.0. (#36467)
Fixed
- Fixed
wazuh-managerstartup failure on RHEL 10 by dropping thelibcryptdependency from embedded Python. (#36782)
Breaking Changes
- Removed unused SSL/TLS transport option from cluster in Manager
Security Fixes
- Hardened FIM database path lookups by migrating to parameterized SQL queries in Agent
- Improved cluster file synchronization security and validation (directory escape prevention, tmp_file path validation, non-merged file path validation, node name format validation)
- Fixed missing agent.host.ip in inventory documents when IP is empty
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Related context
Related tools
Beta — feedback welcome: [email protected]