Skip to content

Update dependency 3proxy/3proxy to v0.9.9 - #99

Closed
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/3proxy-3proxy-0.x
Closed

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/3proxy-3proxy-0.x

Conversation

@renovate

@renovate renovate Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
3proxy/3proxy libraries patch 0.9.7 → 0.9.9

Release Notes

3proxy/3proxy (3proxy/3proxy)

v0.9.9: 3proxy-0.9.9

Compare Source

+ SOCKSv5 UDP: the destination of every datagram is authorized, so ACLs limiting the destination address, host name or port apply to UDP traffic now; the parent proxy and the external address are selected for the destination of the datagram and not for the UDP ASSOCIATE request
+ socks: -U option to control what happens when the destination changes within an UDP association: log it, authorize it, both (default) or neither
+ -C option (for TCP services) to terminate the session as soon as any of the sides closes the connection; by default the session is kept until both sides close it (TCP half-close)
+ timeouts: LINGER value added (11th, default 5), used to deliver buffered data after one of the sides has closed its sending side and as SO_LINGER value on outgoing connections
! Fix: DNS replies are validated now: a reply from an address other than the nameserver the query was sent to, and a reply with a question section not matching the query, are dropped; both were accepted before
! Fix: socket leak with SOCKSv5 UDP ASSOCIATE through a parent proxy, sockets were accumulated in CLOSE_WAIT state until descriptors ran out
! Fix: file descriptor leak in HTTP proxy on the ftp:// request path
! Fix: crash with illegal instruction on some platforms (e.g. some musl based Linux builds), caused by a memcpy on overlapping buffers
! Fix: extip and ha (HAProxy PROXY protocol) parents are applied to SOCKSv5 UDP ASSOCIATE now
! Fix: only socks5 and socks5+ parents are tried for UDP ASSOCIATE, other parent types can not be used for UDP
! Fix: udppm through a SOCKSv5 parent did not work
! Fix: -Ne and -Ni options were never applied, the option letter was not parsed; -Ne is not applied to the UDP ASSOCIATE reply anymore, -Ni is applied to it
! Fix: -4 / -6 handling for UDP in socks; a single UDP association can use both IPv4 and IPv6 destinations now
! Fix: a datagram with a null destination address is dropped now
! Fix: DNS over TCP: a reply which did not fit a single read was never processed
! Documentation: "How to apply ACLs to UDP traffic" added to HOWTO; authentication cache, ACL and UDP notes added to "Optimizing 3proxy for High Load" and to security recommendations

3proxy-0.9.9-x64.zip - Win64 version
3proxy-0.9.9-x86.zip - Win32 version
3proxy-0.9.9-arm64.zip - Windows for ARM64 (ARMv8) version
3proxy-0.9.9-lite.zip - Win32 binaries for older Windows version (Windows
Vista and below)
3proxy-0.9.9.x86_64.deb - x86 64 bit (amd64) DEB package
3proxy-0.9.9.arm64.deb - 64 bit ARM (ARMv8, aarch64) DEB package
3proxy-0.9.9.arm.deb - 32 bit ARM (ARMv7, armhf) DEB package
3proxy-0.9.9.x86_64.rpm - x86 64 bit (amd64) RPM package
3proxy-0.9.9.arm64.rpm - 64 bit ARM (ARMv8, aarch64) RPM package
3proxy-0.9.9.arm.rpm - 32 bit ARM (ARMv7, armhf) RPM package

v0.9.8: 3proxy-0.9.8

Compare Source

!! Fix: use-after-free on the ftp:// request path in HTTP proxy, a request buffer reallocation left a stale pointer; heap corruption, requires authenticated access
!! Fix: buffer overflow in radsend() with an oversized request hostname; RADIUS is experimental, log radius or auth radius with fakeresolve is required to reach it
!! Fix: buffer overflow in smtpp when relaying AUTH LOGIN credentials to a server which offers AUTH PLAIN only; requires authorised access to smtpp
!! Fix: out-of-bounds read in tlspr on a malformed TLS ClientHello
!! Fix: LDAP injection and unsafe counter file names in LdapPlugin; the plugin is unsupported and is not built with 3proxy
!! Fix: password and hash comparison in strong authentication is constant-time now
!! Fix: bounds validation and match/depth limits in pcre filters
+ imapp: IMAPv4 proxy added, supports LOGIN command, AUTH PLAIN and AUTH LOGIN
+ STARTTLS support for smtpp, pop3p, imapp and tlspr, on both client and server side; -x option to disable
+ wolfSSL is supported as an alternative TLS backend, WOLFSSL_CHECK=true selects it (wolfSSL must be built with --enable-opensslextra)
+ Chunked Transfer-Encoding from client is supported by HTTP proxy
+ dnspr: -F option added, fake resolve to redirect traffic
+ ucrt64 build support; static libraries support in Makefile.win
+ minimal and busybox Docker images switched to musl + wolfSSL
- splice() support is not built by default anymore, it is slower than the read/write path for most traffic; add -DWITHSPLICE to build it
! Fix: hashtable item was added with wrong index on table grow; with large username/password tables it could cause a single record to be missing
! Fix: race conditions; stack overflow on FreeBSD
! Fix: generated certificates are X.509 v3 with basicConstraints CA:FALSE and extendedKeyUsage serverAuth, required by Apple TLS stack and by Chrome on macOS/iOS
! Fix: dnspr was broken since udppm rewrite
! Fix: short cleartext passwords failed authentication
! Fix: support PROXY (HAProxy) protocol for intermediate servers
! Fix: maxchild dropped to 100 on config reload if not set explicitly
! Fix: builds for legacy Linux / MacOS version
! Multiple minor bugfixes and code cleanup

Thanks to Tristan for reporting the buffer overflow in radsend(), and to Calif.io in
collaboration with Anthropic for reporting the use-after-free on the ftp:// request path.

3proxy-0.9.8-x64.zip - Win64 version
3proxy-0.9.8-x86.zip - Win32 version
3proxy-0.9.8-arm64.zip - Windows for ARM64 (ARMv8) version
3proxy-0.9.8-lite.zip - Win32 binaries for older Windows version (Windows
Vista and below)
3proxy-0.9.8.x86_64.deb - x86 64 bit (amd64) DEB package
3proxy-0.9.8.arm64.deb - 64 bit ARM (ARMv8, aarch64) DEB package
3proxy-0.9.8.arm.deb - 32 bit ARM (ARMv7, armhf) DEB package
3proxy-0.9.8.x86_64.rpm - x86 64 bit (amd64) RPM package
3proxy-0.9.8.arm64.rpm - 64 bit ARM (ARMv8, aarch64) RPM package
3proxy-0.9.8.arm.rpm - 32 bit ARM (ARMv7, armhf) RPM package


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "monthly"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Sep 1, 2026
@renovate
renovate Bot requested a review from tarampampam as a code owner September 1, 2026 02:01
@renovate
renovate Bot force-pushed the renovate/3proxy-3proxy-0.x branch from e86f319 to abd7ebe Compare September 1, 2026 08:28
@tarampampam tarampampam closed this Sep 1, 2026
@renovate

renovate Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update (0.9.9). You will get a PR once a newer version is released. To ignore this dependency forever, add it to the ignoreDeps array of your Renovate config.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate
renovate Bot deleted the renovate/3proxy-3proxy-0.x branch September 1, 2026 08:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant