发布日期: 2026-01-14
版本号: v2.11.35

此版本包含破坏性变更,默认恢复到之前的行为,需要参考迁移指南启用新功能。同时修复了安全漏洞CVE-2026-22045,并修复了ACME超时及编码字符选项的bug。

更新内容 (中文)

⚠️ 重大变更 ⚠️
正如在 CVE-2025-66490 修复 的评论中所述,此新热修复版本将该行为设为可选启用。
因此,与 v2.11.32 之后的先前热修复版本相比,此版本存在不兼容性变更,但它恢复了该热修复之前存在的默认行为。
请阅读 迁移指南 以启用此功能。

已修复的 CVE:

错误修复:

  • [acme] 为 ACME-TLS/1 挑战握手添加超时机制(#12516,由 LBF38 提交)
  • [server] 将编码字符选项设为可选启用(#12540,由 gndz07 提交)

更新内容 (原始)

:warning: Breaking change :warning: As explained in the comment left on the CVE-2025-66490 fix, this new hotfix version makes the behavior opt-in. As a result, this release is breaking compared to the previous hotfix versions since v2.11.32, but it restores by default the behavior that existed before that hotfix. Please, read the migration guide to enable the feature.

CVE fixed:

Bug fixes:

  • [acme] Add timeout to ACME-TLS/1 challenge handshake (#12516 by LBF38)
  • [server] Make encoded character options opt-in (#12540 by gndz07)

下载链接