DH20.01 release register

51 verified CSF/LFD bug and exploit fixes in DH20.01

The public register documents every hardening requirement shipped in signed release DH20.01. Three operational controls bring the complete qualification matrix to 54 of 54 verified gates.

DCSF

Every security remediation in the signed release

The register covers command boundaries, parsers, files, remote sources, panels, clusters, processes, DNS and firewall state. Statuses are bound to the published package.

51All
51Implemented
51Verified
Filter by status
Visible items: 51
  1. P-01

    Isolate Messenger reCAPTCHA input from every root shell boundary

    Verified
  2. P-02

    Keep remote GLOBAL feeds data-only and unable to deliver advanced rules

    Verified
  3. P-03

    Protect Messenger files from symlink, hardlink and replacement races

    Verified
  4. P-04

    Parse CIDR /0 explicitly and permit it only through caller policy

    Verified
  5. P-05

    Require pinned RSA-3072 signatures, SHA-256-bound metadata and rollback checks for updates

    Verified
  6. P-06

    Harden the DirectAdmin privileged bridge and verify identity transitions

    Verified
  7. P-07

    Run privileged Perl entry points in taint mode with a minimal environment

    Verified
  8. P-08

    Generate a protected host-local key for the standalone interface

    Verified
  9. P-09

    Bound standalone UI workers, requests, searches, pre-authentication time and emitted output

    Verified
  10. P-10

    Add CSPRNG sessions, CSRF protection, secure headers and modern TLS to the standalone UI

    Verified
  11. P-11

    Encode untrusted output at the final rendering boundary in every UI adapter

    Verified
  12. P-12

    Classify Dovecot 2.4 success and failure variants without known false positives

    Verified
  13. P-13

    Ignore managesieve-login consistently in every applicable profile

    Verified
  14. P-14

    Restrict custom regex results to validated TCP or UDP ports from 1 to 65535

    Verified
  15. P-15

    Enforce HTTPS with certificate and hostname verification for remote sources

    Verified
  16. P-16

    Validate download status, size and format before atomic last-good replacement

    Verified
  17. P-17

    Propagate restore failures and retain the last working firewall state

    Verified
  18. P-18

    Extract ZIP blocklists with strict limits and atomic replacement

    Verified
  19. P-19

    Bound log records before regex processing and remove catastrophic patterns

    Verified
  20. P-20

    Authenticate, frame and resource-bound all cluster traffic

    Verified
  21. P-21

    Isolate LF_DIRWATCH offenders and recover monitoring automatically

    Verified
  22. P-22

    Apply LF_SCRIPT_PERM changes only to the verified open inode

    Verified
  23. P-23

    Keep secrets out of arguments, URLs, unsafe files and diagnostic bodies

    Verified
  24. P-24

    Use one strict canonical API for IPv4, IPv6 and CIDR normalization

    Verified
  25. P-25

    Validate the final mail envelope and invoke sendmail without a shell

    Verified
  26. P-26

    Resolve exact syslog user names, including names beginning with an underscore

    Verified
  27. P-27

    Separate display DNS data from security-authorisation cache state

    Verified
  28. P-28

    Match trusted hostnames only as exact names or DNS-label suffixes

    Verified
  29. P-29

    Canonicalise PTR data before cache, logs, mail, HTML or configuration use

    Verified
  30. P-30

    Bound DNS verification and caches by time, concurrency, size and complexity

    Verified
  31. P-31

    Allow privileged CyberPanel mutations only through protected POST actions

    Verified
  32. P-32

    Remove predictable and followable temporary files from every installer

    Verified
  33. P-33

    Prevent raw-byte record readers from splitting inside multibyte characters

    Verified
  34. P-34

    Register, authorise and bound every persistent store consumed by root

    Verified
  35. P-35

    Use one unambiguous transactional grammar for temporary firewall rules

    Verified
  36. P-36

    Render alert templates once and prevent untrusted MIME structure injection

    Verified
  37. P-37

    Drop Messenger v1 privileges irreversibly and close inherited descriptors

    Verified
  38. P-38

    Contain Messenger v2 and v3 webroots and generated webserver configuration

    Verified
  39. P-39

    Verify the Messenger identity and make each instance lifecycle transactional

    Verified
  40. P-40

    Build and install releases from a closed, verified artifact inventory

    Verified
  41. P-41

    Transport authenticated panel requests without invoking a shell

    Verified
  42. P-42

    Validate and install remote Geo and ASN datasets as one last-good transaction

    Verified
  43. P-43

    Bound log-record allocation before a complete attacker-controlled line enters memory

    Verified
  44. P-44

    Bind process actions to kernel identity rather than a reusable PID or socket inode

    Verified
  45. P-45

    Ensure fork-bomb handling never treats a session ID as a process-group ID

    Verified
  46. P-46

    Remove command text and custom pignore regexes as process identity or action authority

    Verified
  47. P-47

    Prevent attacker-controlled comm bytes from shifting procfs identity fields or hiding a process

    Verified
  48. P-48

    Prevent executable exceptions from bypassing accounting across UID, service or supervisor boundaries

    Verified
  49. P-49

    Bound procfs scanning per object, per UID and globally with cross-UID fairness

    Verified
  50. P-50

    Bound lock-hang recovery and never signal a target parsed from lock-file bytes

    Verified
  51. P-51

    Block secondary InterWorx NodeWorx accounts from DCSF unless they hold native firewall authority

    Verified
DCSF

Three operational release controls

Beyond the 51 remediations, the matrix covers installation profiles, CC_DENY reply handling and Docker policy preservation. All three controls are verified.

O-01

Require an explicit testing or production installation profile and expose testing mode in health checks

Verified
O-02

Preserve replies to locally initiated connections under CC_DENY without admitting new inbound traffic

Verified
O-03

Preserve Docker-owned chains and DOCKER-USER policy through firewall restart and rollback

Verified
Released

All 51 security fixes are verified

The complete DH20.01 matrix passed 54 of 54 release gates. The signed DCSF 15.10.4 package is publicly available.

Download release