Repository navigation
Update dependency 3proxy/3proxy to v0.9.9 - #99
Closed
renovate[bot] wants to merge 1 commit into
Closed
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/3proxy-3proxy-0.x
branch
from
September 1, 2026 08:28
e86f319 to
abd7ebe
Compare
Contributor
Author
Renovate Ignore NotificationBecause you closed this PR without merging, Renovate will ignore this update ( If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.9.7→0.9.9Release Notes
3proxy/3proxy (3proxy/3proxy)
v0.9.9: 3proxy-0.9.9Compare Source
+ SOCKSv5 UDP: the destination of every datagram is authorized, so ACLs limiting the destination address, host name or port apply to UDP traffic now; the parent proxy and the external address are selected for the destination of the datagram and not for the UDP ASSOCIATE request
+ socks: -U option to control what happens when the destination changes within an UDP association: log it, authorize it, both (default) or neither
+ -C option (for TCP services) to terminate the session as soon as any of the sides closes the connection; by default the session is kept until both sides close it (TCP half-close)
+ timeouts: LINGER value added (11th, default 5), used to deliver buffered data after one of the sides has closed its sending side and as SO_LINGER value on outgoing connections
! Fix: DNS replies are validated now: a reply from an address other than the nameserver the query was sent to, and a reply with a question section not matching the query, are dropped; both were accepted before
! Fix: socket leak with SOCKSv5 UDP ASSOCIATE through a parent proxy, sockets were accumulated in CLOSE_WAIT state until descriptors ran out
! Fix: file descriptor leak in HTTP proxy on the ftp:// request path
! Fix: crash with illegal instruction on some platforms (e.g. some musl based Linux builds), caused by a memcpy on overlapping buffers
! Fix: extip and ha (HAProxy PROXY protocol) parents are applied to SOCKSv5 UDP ASSOCIATE now
! Fix: only socks5 and socks5+ parents are tried for UDP ASSOCIATE, other parent types can not be used for UDP
! Fix: udppm through a SOCKSv5 parent did not work
! Fix: -Ne and -Ni options were never applied, the option letter was not parsed; -Ne is not applied to the UDP ASSOCIATE reply anymore, -Ni is applied to it
! Fix: -4 / -6 handling for UDP in socks; a single UDP association can use both IPv4 and IPv6 destinations now
! Fix: a datagram with a null destination address is dropped now
! Fix: DNS over TCP: a reply which did not fit a single read was never processed
! Documentation: "How to apply ACLs to UDP traffic" added to HOWTO; authentication cache, ACL and UDP notes added to "Optimizing 3proxy for High Load" and to security recommendations
3proxy-0.9.9-x64.zip - Win64 version
3proxy-0.9.9-x86.zip - Win32 version
3proxy-0.9.9-arm64.zip - Windows for ARM64 (ARMv8) version
3proxy-0.9.9-lite.zip - Win32 binaries for older Windows version (Windows
Vista and below)
3proxy-0.9.9.x86_64.deb - x86 64 bit (amd64) DEB package
3proxy-0.9.9.arm64.deb - 64 bit ARM (ARMv8, aarch64) DEB package
3proxy-0.9.9.arm.deb - 32 bit ARM (ARMv7, armhf) DEB package
3proxy-0.9.9.x86_64.rpm - x86 64 bit (amd64) RPM package
3proxy-0.9.9.arm64.rpm - 64 bit ARM (ARMv8, aarch64) RPM package
3proxy-0.9.9.arm.rpm - 32 bit ARM (ARMv7, armhf) RPM package
v0.9.8: 3proxy-0.9.8Compare Source
!! Fix: use-after-free on the ftp:// request path in HTTP proxy, a request buffer reallocation left a stale pointer; heap corruption, requires authenticated access
!! Fix: buffer overflow in radsend() with an oversized request hostname; RADIUS is experimental, log radius or auth radius with fakeresolve is required to reach it
!! Fix: buffer overflow in smtpp when relaying AUTH LOGIN credentials to a server which offers AUTH PLAIN only; requires authorised access to smtpp
!! Fix: out-of-bounds read in tlspr on a malformed TLS ClientHello
!! Fix: LDAP injection and unsafe counter file names in LdapPlugin; the plugin is unsupported and is not built with 3proxy
!! Fix: password and hash comparison in strong authentication is constant-time now
!! Fix: bounds validation and match/depth limits in pcre filters
+ imapp: IMAPv4 proxy added, supports LOGIN command, AUTH PLAIN and AUTH LOGIN
+ STARTTLS support for smtpp, pop3p, imapp and tlspr, on both client and server side; -x option to disable
+ wolfSSL is supported as an alternative TLS backend, WOLFSSL_CHECK=true selects it (wolfSSL must be built with --enable-opensslextra)
+ Chunked Transfer-Encoding from client is supported by HTTP proxy
+ dnspr: -F option added, fake resolve to redirect traffic
+ ucrt64 build support; static libraries support in Makefile.win
+ minimal and busybox Docker images switched to musl + wolfSSL
- splice() support is not built by default anymore, it is slower than the read/write path for most traffic; add -DWITHSPLICE to build it
! Fix: hashtable item was added with wrong index on table grow; with large username/password tables it could cause a single record to be missing
! Fix: race conditions; stack overflow on FreeBSD
! Fix: generated certificates are X.509 v3 with basicConstraints CA:FALSE and extendedKeyUsage serverAuth, required by Apple TLS stack and by Chrome on macOS/iOS
! Fix: dnspr was broken since udppm rewrite
! Fix: short cleartext passwords failed authentication
! Fix: support PROXY (HAProxy) protocol for intermediate servers
! Fix: maxchild dropped to 100 on config reload if not set explicitly
! Fix: builds for legacy Linux / MacOS version
! Multiple minor bugfixes and code cleanup
Thanks to Tristan for reporting the buffer overflow in radsend(), and to Calif.io in
collaboration with Anthropic for reporting the use-after-free on the ftp:// request path.
3proxy-0.9.8-x64.zip - Win64 version
3proxy-0.9.8-x86.zip - Win32 version
3proxy-0.9.8-arm64.zip - Windows for ARM64 (ARMv8) version
3proxy-0.9.8-lite.zip - Win32 binaries for older Windows version (Windows
Vista and below)
3proxy-0.9.8.x86_64.deb - x86 64 bit (amd64) DEB package
3proxy-0.9.8.arm64.deb - 64 bit ARM (ARMv8, aarch64) DEB package
3proxy-0.9.8.arm.deb - 32 bit ARM (ARMv7, armhf) DEB package
3proxy-0.9.8.x86_64.rpm - x86 64 bit (amd64) RPM package
3proxy-0.9.8.arm64.rpm - 64 bit ARM (ARMv8, aarch64) RPM package
3proxy-0.9.8.arm.rpm - 32 bit ARM (ARMv7, armhf) RPM package
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.