NetBird

Developer Tools

A WireGuard-based overlay network that connects your machines with zero configuration.

Latest v0.76.3 · by NetBirdWebsitenetbirdio/netbird

Release activity

Release activity — 10 releases across 10 days since Jul 13, 2026. Each cell is one day; darker means more releases that day. Nothing is recorded before Jul 13, 2026. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026
Monday1 release on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026No releases on Aug 10, 2026
Tuesday1 release on Jul 14, 2026No releases on Jul 21, 20261 release on Jul 28, 2026No releases on Aug 4, 2026No releases on Aug 11, 2026
Wednesday1 release on Jul 15, 2026No releases on Jul 22, 20261 release on Jul 29, 2026No releases on Aug 5, 2026
ThursdayNo releases on Jul 16, 20261 release on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026
Friday1 release on Jul 17, 2026No releases on Jul 24, 20261 release on Jul 31, 20261 release on Aug 7, 2026
SaturdayNo releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 20261 release on Aug 8, 2026

10 releases since Jul 13, 2026

Changelog

v0.76.3

Added 1
  • Add Grafana dashboard for licensed management
Changed 5
  • Prewarm posture check cache on network map generation
  • Detect community GHCR images during enterprise migration
  • Disambiguate the connection_type metric tag
  • Track affected peers for user updates
  • Deny reverse proxy access to pending and blocked users
Fixed 1
  • Re-arm the WireGuard watcher after a lazy wake
What's Changed

Full Changelog: https://github.com/netbirdio/netbird/compare/v0.76.2...v0.76.3

View originalPermalink
How v0.76.3 went

v0.76.2

Added 2
  • Declare GTK4/WebKitGTK runtime deps for the Linux UI packages
  • Generic gRPC extension seam for external modules
Changed 3
  • Resolve agent network permissions per submodule
  • Reuse the persisted configuration when enrolling on Android
  • Update wails to v3.0.0-beta.3
Fixed 15
  • Handle interface lookup errors in iOS DNS index helper
  • Remove duplicate Login RPCs from the iOS SDK
  • Fix handling of empty network map during decode and encode
  • Keep the account email backing the SSO login hint correct
  • Create the Android fake IP manager lazily on DNS flag enable
  • Serialize Android tunnel reconfiguration callbacks
What's Changed
New Contributors

Full Changelog: https://github.com/netbirdio/netbird/compare/v0.76.1...v0.76.2

View originalPermalink
How v0.76.2 went

v0.76.1

Added 1
  • Support Android session expiry handling
Changed 4
  • Stop and remove the daemon on netbird-ui cask uninstall
  • Remove cluster tag from proxy metrics
  • Restrict debug bundle log path and upload destinations
  • Management-owned LLM pricing: file-backed defaults
Fixed 2
  • Fix daemon lock order inversion between SetConfig and login
  • Fix expression order in legacy nftables route rules
What's Changed
Agent Network
New Contributors

Full Changelog: https://github.com/netbirdio/netbird/compare/v0.76.0...v0.76.1

View originalPermalink
How v0.76.1 went

v0.76.0

Added 2
  • Expose RenameProfile in the Android profile manager binding
  • Export peer details for Android
Changed 9
  • Derive each local caller's identity from the kernel in the daemon's local control interface
  • Serve a named pipe instead of loopback TCP on Windows for the daemon's local control interface
  • Automatically migrate existing Windows installations to use the named pipe instead of loopback TCP
  • Build UI release binaries with the production tag
  • Unify route selection in the route manager
  • Parse NB_LAZY_CONN_INACTIVITY_THRESHOLD as a Go duration
Fixed 4
  • Escape dots in interface names for sysctl configuration
  • Serialize iOS tunnel reconfiguration callbacks
  • Add explicit accountID check when deleting a user
  • Fix UI crash on Windows builds without dark-mode support
Deprecated 1
  • Deprecate legacy Dex and Zitadel getting-started scripts
Security 1
  • Fix local privilege escalation in the client daemon by requiring root or administrator privileges to enable the SSH server, enable SSH root login, disable SSH authentication, or change the management URL or deregister the peer while the SSH server is enabled
Security

Fixes a local privilege escalation in the client daemon (https://github.com/netbirdio/netbird/security/advisories/GHSA-qcpp-8vwj-hhwr). The daemon's local control interface accepted any local caller without authentication, so an unprivileged user on the same machine could enable the embedded SSH server, turn on SSH root login and disable SSH authentication, and then open a root shell. Every version from 0.5.0 to 0.75.1 is affected: on Linux, macOS and FreeBSD through the world-writable Unix socket, and on Windows through the loopback TCP listener, which carried no caller identity at all. Reported by @neewek.

The daemon now derives each local caller's identity from the kernel and requires root, or an administrator on Windows, to enable the SSH server, enable SSH root login, disable SSH authentication, or to change the management URL or deregister the peer while that profile has the SSH server enabled. On Windows it serves a named pipe instead of loopback TCP, and existing installations are migrated automatically.

Upgrade note: if you enable any of those settings from a script or an unprivileged session, run the command with sudo, or from an elevated prompt on Windows. Turning them off is unchanged, and so is everything else on the socket.

Learn more here

What's Changed
New Contributors

Full Changelog: https://github.com/netbirdio/netbird/compare/v0.75.1...v0.76.0

View originalPermalink
How v0.76.0 went

v0.75.1

Added 4
  • Added prompt cache token and cost accounting to Agent Network usage
  • Added support for Claude Opus 5
  • Scoped Agent Network model allowlists per policy, group, and provider
  • Added ReapplyMatching support to the dedicated AllowedIPsRefCounter
Changed 6
  • Reconcile routed AllowedIPs when a lazy connection becomes idle
  • Fetch FreeBSD port files from the GitHub mirror instead of cgit
  • Export agent version information for iOS
  • Use platform-specific installer URLs for manual update downloads
  • Exit the GUI immediately when the Windows session ends
  • Restored the rootless-latest Docker image tag
Fixed 2
  • Restored the missing backup.Reset behavior
  • Fixed stale routing peers after removing overlapping-prefix networks
Release Notes for v0.75.1
What's New
Agent Network
Client Improvements
Infrastructure & Miscellaneous

Full Changelog: https://github.com/netbirdio/netbird/compare/v0.75.0...v0.75.1

View originalPermalink
How v0.75.1 went

v0.75.0

Added 6
  • Rebuilt the desktop client as a Wails v3 application with a React and TypeScript frontend, replacing the Fyne UI
  • Added internationalization with 10 locales (English, German, Spanish, French, Hungarian, Italian, Japanese, Portuguese, Russian, and Simplified Chinese)
  • Added a new system tray with per-platform theme-aware icons, including a native XEmbed host and theme watcher on Linux
  • Extended the daemon API with status stream subscription, an event stream, networks and exit-node selection endpoints, and richer full status with probe throttling
  • Added a JSON gateway for the NetBird daemon, exposing the daemon API over HTTP/JSON
  • Introduced client-side event aggregation
Changed 8
  • Improved session handling with an auth session watcher, pending login flow, session-expiration dialog and tray notifications, and netbird login improvements
  • Enabled launch-on-login by default on fresh GUI installs, managed through the daemon as the single source of truth
  • Made the client connect immediately on profile selection, except while managing profiles
  • Brought the connection up in Go after SSO login for a faster, more reliable post-login connect
  • Offloaded client config generation to the client, reducing work on the management server
  • Warmed lazy connections from the DNS resolver so lazily-connected peers come up faster
  • Raised the relay early-message buffer cap to 10,000 to avoid dropping relayed handshakes
  • Updated Wails to v3.0.0-alpha2.117
Fixed 5
  • Fixed the browser dialog not closing during the renew-session flow
  • Fixed forwarder peers never being excluded from lazy connections
  • Fixed WGWatcher silently failing to restart on fast disconnect/reconnect
  • Cleared stale UDP checksums in the eBPF XDP proxy after port rewrite
  • Fixed a nil-context panic in the iOS dynamic route resolver
Security 1
  • Enforced MDM disableAutostart on every GUI launch, not just fresh installs
Release Notes for v0.75.0
New Feature: Redesigned Desktop Client

This release ships a complete rewrite of the desktop client. We went ahead and replaced the old Fyne-based tray application with a new Wails v3 app backed by a React and TypeScript frontend, and it is a massive upgrade. You get a proper main connection view, an exit-node switcher, a networks and peers browser with detail panels, profile management, full settings, debug-bundle creation, and a first-run welcome flow, all in one place instead of buried in a tray menu. #6473 by @pappz and @heisbrot

The new UI is also translated into 10 languages now, and session handling got a lot smarter, so you actually know when your session is about to expire instead of finding out the hard way. Do note that launch-on-login is now enabled by default on fresh GUI installs, so if you manage devices through MDM, the disableAutostart setting is enforced on every launch to keep that under your control.

  • Rebuilt the desktop client as a Wails v3 application with a React + TypeScript frontend, replacing the Fyne UI. #6473
  • Added internationalization with 10 locales (English, German, Spanish, French, Hungarian, Italian, Japanese, Portuguese, Russian, and Simplified Chinese), shared between the tray and the frontend. #6473, #6790 by @s-shimizu-clpl
  • Added a new system tray with per-platform theme-aware icons, including a native XEmbed host and theme watcher on Linux. #6473
  • Improved session handling with an auth session watcher, pending login flow, session-expiration dialog and tray notifications, and netbird login improvements. #6473
  • Extended the daemon API with status stream subscription, an event stream, networks and exit-node selection endpoints, and richer full status, with probe throttling to protect the daemon from UI-driven request storms. #6473
  • Enabled launch-on-login by default on fresh GUI installs, managed through the daemon as the single source of truth (HKCU on Windows). #6738 by @mlsmaycon
  • Enforced MDM disableAutostart on every GUI launch, not just fresh installs. #6782 by @riccardomanfrin

Learn more:

What's Changed
Desktop Client Improvements
  • Made the client connect immediately on profile selection, except while managing profiles. #6838 by @pappz
  • Brought the connection up in Go after SSO login for a faster, more reliable post-login connect. #6744 by @mlsmaycon
  • Kept the session deadline visible across reconnects. #6847 by @pappz
  • Fixed the browser dialog not closing during the renew-session flow. #6745 by @heisbrot
  • Disconnected the daemon on GUI quit via an async Down call. #6796 by @pappz
  • Restored residual state in foreground mode before login. #6707 by @dfry
  • Clarified the outdated client overlay wording. #6718 by @heisbrot
  • Used menu-bar wording on the macOS welcome screen. #6810 by @heisbrot
  • Added SSO login flow timing instrumentation. #6717 by @mlsmaycon
  • Updated Wails to v3.0.0-alpha2.117. #6837 by @pappz
Client Improvements
  • Added a JSON gateway for the NetBird daemon, exposing the daemon API over HTTP/JSON. #6272 by @jnfrati
  • Introduced client-side event aggregation. #6627 by @dmitri-netbird
  • Offloaded client config generation to the client, reducing work on the management server. #6711 by @dmitri-netbird
  • Warmed lazy connections from the DNS resolver so lazily-connected peers come up faster. #6854 by @mlsmaycon
  • Fixed forwarder peers never being excluded from lazy connections. #6674 by @riccardomanfrin
  • Fixed WGWatcher silently failing to restart on fast disconnect/reconnect. #6664 by @riccardomanfrin
  • Cleared stale UDP checksums in the eBPF XDP proxy after port rewrite. #6861 by @lixmal
  • Raised the relay early-message buffer cap to 10,000 to avoid dropping relayed handshakes. #6752 by @riccardomanfrin
  • Fixed a nil-context panic in the iOS dynamic route resolver. #6848 by @pappz
  • Fixed a DNS probe listener panic on unparseable local addresses. #6797 by @pappz
  • Fixed the browser (WASM) relay WebSocket close and raised the RDP dial timeout. #6684 by @lixmal
  • Included system events in status conversion. #6746 by @lixmal
  • Refreshed WireGuard stats in mobile debug bundles. #6814 by @pappz
  • Distinguished empty vs. corrupt state in debug diagnostics. #6816 by @pappz
Management Improvements
  • Added the dashboard_features account setting #6742 and the agent_network_only account setting #6736, with agent_network_only requiring dashboard_features.agent_network to be enabled #6750 — all by @mlsmaycon
  • Added traffic filters for source and destination ID. #6697 by @pascal-fischer
  • Allowed disabling the device code flow when using Dex. #6809 by @pascal-fischer
  • Propagated auth grant types for the combined server. #6817 by @pascal-fischer
  • Built routes for the peer cache on network map components #6780 and added component types #6866 — both by @pascal-fischer
  • Fixed fetching of missing settings in the GetAccount call. #6800 by @dmitri-netbird
  • Fixed a duplicate operationId in the OpenAPI spec. #6734 by @CoderSufiyan
  • Enabled pprof via an environment variable. #6778 by @pascal-fischer
  • Added logging to ephemeral peer deletion. #6747 by @pascal-fischer
Agent Network
  • Added Kimi (Moonshot AI) to the provider catalog. #6853 by @mlsmaycon
  • Added Bedrock cost-allocation metadata plus a per-provider metadata_disabled option. #6791 by @mlsmaycon
  • Matched Bedrock provider models against the normalized request model. #6773 by @mlsmaycon
  • Probed the agent-network endpoint with a GET instead of getent. #6867 by @mlsmaycon
  • Fixed the proxy multi-stage Docker build. #6864 by @mlsmaycon
Relay Improvements
  • Trusted X-Real-Ip headers only from configured trusted proxies. #6833 by @pappz
  • Removed the deprecated Hello handshake and gob token decode. #6783 by @lixmal
Self-Hosting Improvements
  • Added a unified admin CLI for self-hosted helpers. #6507 by @jnfrati
  • Simplified the enterprise bootstrap. #6869 by @bcmmbaga
Internal, CI, and Docs
  • Copied the trustedproxy package into the Docker build context. #6851 by @pappz
  • Ran pnpm install with --ignore-scripts in frontend CI. #6859 by @pappz
  • Re-generated gateway proto files. #6696 by @jnfrati
  • Fixed flaky tests in account settings and event aggregation #6811, #6710 by @dmitri-netbird, and in the peer-connect handshake wait #6871 by @riccardomanfrin
  • Updated the Agent Network readme. #6699 by @braginini
New Contributors
  • @CoderSufiyan made their first contribution in #6734
  • @s-shimizu-clpl made their first contribution in #6790

Full Changelog: https://github.com/netbirdio/netbird/compare/v0.74.7...v0.75.0

View originalPermalink
How v0.75.0 went

v0.74.7

Changed 1
  • Bind netstack SOCKS5 proxy to 127.0.0.1 by default
Fixed 5
  • Handle QUIC connections concurrently in relay to prevent handshake head-of-line blocking
  • Reject leading hyphen in getent input to prevent flag injection
  • Sanitize peer FQDN/hostname in generated SSH config
  • Disable gVisor TCP RACK loss detection on Windows
  • Evaluate IP fragments against firewall ACLs
What's Changed

Full Changelog: https://github.com/netbirdio/netbird/compare/v0.74.6...v0.74.7

View originalPermalink
How v0.74.7 went

v0.74.5

Changed 1
  • Enforce model allowlist for URL-routed providers (Bedrock/Vertex) in proxy
Removed 1
  • Remove proxy peer stale deduplication logic from management
What's Changed

Full Changelog: https://github.com/netbirdio/netbird/compare/v0.74.4...v0.74.5

View originalPermalink
How v0.74.5 went

v0.75.0-rc.6

Pre-release
Added 6
  • Introduce client-side event aggregation
  • Add JSON gateway for NetBird daemon
  • Add traffic filters for source and destination ID
  • Add SSO login flow timing instrumentation
  • Add agent_network_only account setting
  • Add dashboard_features account setting
Changed 3
  • Enable launch-on-login by default on fresh GUI installs
  • Require dashboard_features.agent_network when enabling agent_network_only
  • Include system events in status conversion
Fixed 5
  • Fix MDM managementURL conflict on default-port URL echo
  • Re-generate gateway proto files
  • Fix browser relay WebSocket close and raise RDP dial timeout
  • Fix duplicate operationId in OpenAPI spec
  • Bring the connection up in Go after SSO login
What's Changed
New Contributors

Full Changelog: https://github.com/netbirdio/netbird/compare/v0.74.2...v0.75.0-rc.6

View originalPermalink
How v0.75.0-rc.6 went
View all

Discussion