Skip to content
release
BETA
Releases
Tools
Vendors
Trending
$refs.securityHub.focus())"
:aria-expanded="open"
aria-haspopup="menu"
class="inline-flex items-center gap-1 px-3 py-1.5 rounded text-[13px] font-medium transition-colors text-[var(--text-secondary)] dark:text-[var(--text-muted)] hover:text-[var(--text-primary)] dark:hover:text-[var(--text-primary)] hover:bg-[var(--surface-hover)] dark:hover:bg-[var(--surface-elevated)]"
>
Security
Tools
/
ferron
/
Releases
FE
Release history
ferron releases
A fast, memory-safe web server written in Rust.
3.0.0-beta.1
New feature
·
29d
Notable features
CLI utility for hashing passwords CLI utility for pre‑compressing static files CLI utility for translating Ferron 2 configurations into Ferron 3 ones
Full changelog
Added
CLI utility for hashing passwords.
CLI utility for pre-compressing static files.
CLI utility for translating Ferron 2 configurations into Ferron 3 ones.
CLI utility for zero-configuration serving.
Changed
Non-existent webroots now lead to 404 Not Found errors instead of 500 Internal Server Error errors.
Fixed
Partial hostname resolution match in HTTP server could lead to incorrect routing.
Redirects configured with status directive didn't have some placeholder locations (such as $1) replaced when using a regex match.
Redirects configured with status directive didn't lead to any destination.
Reverse proxy was sometimes routed to wrong backend server.
Some default cache paths were unwritable in some cases.
Unknown directives in global blocks for status directive (even though they're known in host blocks) caused the web server to fail to start.
When using OTLP, access logs were emitted with "access_log" body, not actual access logs.
2.7.0
Security relevant
·
2mo
Security fixes
Path traversal when URL sanitizer disabled and path canonicalization failed Proxy header leak in CGI/FastCGI/SCGI (httpoxy)
Notable features
DNSimple DNS provider support IP-based TLS certificate support JSON-format access logs
2.6.0
New feature
·
2mo
Breaking changes
Rego-based subconditions deprecated and will be removed in future release
Notable features
Dynamic SRV-based backend discovery File size-based log rotation Reusable KDL configuration snippets
2.5.5
Bugfix
·
3mo
- Fixed OTLP data not being sent after configuration reloads.
2.5.4
Bugfix
·
3mo
- Fixed high CPU usage after configuration reloads caused by the OCSP stapler.
2.5.3
Bugfix
·
3mo
- Fixed process-related metrics not being sent at all.
2.5.2
Maintenance
·
3mo
- Improved memory usage during configuration reloads.
2.5.1
Bugfix
·
3mo
- Fixed graceful shutdowns when reloading the server configuration.
2.5.0
New feature
·
3mo
Notable features
Logging to standard I/O TLS certificate and key persistence Forwarded HTTP header support
2.4.1
Bugfix
·
4mo
- Fixed a rarely occurring crash when upgrading backend server's HTTP connection as a reverse proxy.
2.4.0
Bug fix
·
4mo
Notable features
Bunny.net, DigitalOcean, OVH DNS providers HTTP Basic authentication for forward proxying
2.3.2
Maintenance
·
4mo
- The server now gracefully handles canceled I/O operations that could previously cause 502 Bad Gateway errors (when io_uring is disabled). - The server now gracefully handles canceled I/O operations that could previously cause a crash under rare conditions (when io_uring is enab
2.3.1
Maintenance
·
4mo
- The server now gracefully handles canceled I/O operations that could previously cause a crash under rare conditions (when io_uring is disabled).
2.3.0
New feature
·
4mo
Breaking changes
Removed configuration directive for maximum idle kept-alive connection pool in reverse proxy
Security fixes
Fixed XSS in server administrator email configuration Fixed ACME EAB Base64 HMAC parsing
Notable features
Reverse proxy connection metrics URL sanitizer disable option TCP concurrency limits
© 2026 releaseport. All rights reserved.
Feed
Tools
Feeds
Security
Brief
Search tools, categories, lists, and users
Use ↑↓ to navigate, Enter to open, Esc to close
No results for " "
⌘K to open
↑↓ navigate
⏎ open