AdGuard Home has a critical vulnerability where attackers can completely bypass authentication by establishing an HTTP/2 connection via the h2c protocol and then access all administrative functions without providing any login credentials.
AdGuard Home
AdGuard02.06.2026
Upgrade assessment
SicherheitsrelevantZeitnah aktualisieren
Derived automatically from release, repo and CVE data — no judgment by a language model.
AdGuard Home and dnsproxy have a vulnerability in DNS forwarding over DoQ where the DNS ID is set to zero, reducing randomness and potentially allowing attackers to manipulate DNS queries.
Security update fixes path traversal vulnerability in GLiNET mode and adds new query parameter for query log
Security update fixes critical path traversal vulnerability in GLiNET mode and corrects blocked services issues
YAML configuration now supports day units for duration values and fixes DNS caching issue with disabled DNSSEC
Hotfix for DNS cache issues and support for day units in YAML configuration with rollback warning
Critical security vulnerability in DNS-over-QUIC and DNS-over-HTTPS fixed, Go version updated and various UI issues resolved
Security update with Go upgrade, new query parameter for querylog API and various UI improvements
Security updates for frontend libraries and Go version, configuration schema change from version 33 to 34 with new DoH configuration
Security update with frontend libraries and Go version updates plus fixes for domain-specific upstreams and TLS configuration
Configuration schema updated from version 33 to 34 with new DoH configuration structure and fixed launchd service status reporting
Security update with Go version upgrade, improved HTTP/2 authentication, and fix for client blocking functionality
Critical security vulnerability fixed that allowed authentication bypass through HTTP/2 Cleartext requests
AdGuard Home v0.107.72 introduces automatic TLS certificate reloading, extends API with new parameters, and changes configuration schema from version 32 to 33
Go version updated to fix security vulnerabilities, TLS certificate tracking added and Docker permission issues resolved
Configuration schema update to version 33 with new ignored_enabled fields for querylog and statistics, fixes for server crashes and DNS cache issues
Hotfix repairs broken optimistic DNS cache and adds new configuration options for maximum age and TTL of stale answers
Security update to Go 1.25.5 and new configuration options for optimistic DNS cache with schema change from version 31 to 32
Security update with Go version upgrade, new start_time field in status API, improved DNS cache logic and fixes for macOS configuration
Beta update with Go security update, new start_time field in status API, redesigned blocked services UI, and fix for macOS installation issue
Bug fixes for DHCP settings and DNS Rewrite modal along with build system updates
Beta update with security improvements, new DNS rewrite settings and configuration schema changes
Added new feature to enable and disable DNS rewrite rules, updated configuration schema from version 30 to 31, upgraded Go version for security updates
Security update to Go 1.25.2, added new API fields for blocked services and DNS rebind protection filter
New DNS filter against rebinding attacks, optimization of filtering rules and fix for configuration file overwrites
Beta update with configurable default HTTP port via environment variable, optimized rule filtering and improved logging
Fixes authentication errors in proxy setups, updates Go version for security patches and improves HTTP header handling
Security update with Go 1.25.1, improved User-Agent header, snap package based on core24, and fixes for authentication and API endpoint issues
DNS cache configuration reworked with new cache_enabled field and schema update to version 30
Configuration schema updated to version 30 with new dns.cache_enabled field for explicit DNS cache control
Security update with Go version upgrade and fixes for TTL calculation and DNSCrypt validation
Beta update with new blockable services (ChatGPT, Claude, DeepSeek, Odysee) and updated dependencies