Wazuh

Developer Tools

The open-source security platform.

Latest v4.14.7 · by WazuhWebsitewazuh/wazuh

Release activity

Release activity — 10 releases across 9 days since Feb 11, 2026. Each cell is one day; darker means more releases that day. Nothing is recorded before Feb 11, 2026. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Apr 19, 2026No releases on Apr 26, 2026No releases on May 3, 2026No releases on May 10, 2026No releases on May 17, 2026No releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026
MondayNo releases on Apr 20, 2026No releases on Apr 27, 2026No releases on May 4, 2026No releases on May 11, 2026No releases on May 18, 2026No releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026
TuesdayNo releases on Apr 21, 2026No releases on Apr 28, 2026No releases on May 5, 2026No releases on May 12, 2026No releases on May 19, 2026No releases on May 26, 2026No releases on Jun 2, 2026No releases on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 20261 release on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026
WednesdayNo releases on Apr 22, 2026No releases on Apr 29, 2026No releases on May 6, 2026No releases on May 13, 2026No releases on May 20, 2026No releases on May 27, 2026No releases on Jun 3, 2026No releases on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026
Thursday1 release on Apr 23, 2026No releases on Apr 30, 2026No releases on May 7, 2026No releases on May 14, 20261 release on May 21, 2026No releases on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 20261 release on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 20262 releases on Jul 30, 2026No releases on Aug 6, 2026
FridayNo releases on Apr 24, 2026No releases on May 1, 2026No releases on May 8, 2026No releases on May 15, 2026No releases on May 22, 2026No releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 20261 release on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026
SaturdayNo releases on Apr 25, 2026No releases on May 2, 2026No releases on May 9, 2026No releases on May 16, 2026No releases on May 23, 2026No releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026

10 releases since Feb 11, 2026, busiest day 2

Changelog

v4.14.7

Wazuh v4.14.7

Added 2
  • Add IP address validation to the ip-customblock active response to prevent malformed input in file path operations
  • Add a null check for inode and device fields in the FIM whodata event handler
Changed 1
  • Update aiohttp, cryptography, PyJWT, python-multipart and starlette Python dependencies
Fixed 15
  • Improve cluster payload buffer allocation strategy
  • Improve cluster archive decompression limits
  • Improve cluster worker file path validation
  • Improve API authentication stability with bounded thread pools, regex timeouts and payload size limits
  • Fix AWS SQS subscriber wodle resolving the wrong AWS account for cross-account iam_role_arn configurations
  • Fix agent keepalive scheduling after a system clock rollback causing false Disconnected status
Removed 1
  • Remove deprecated wazuh-dbd daemon and database_output configuration
Manager
Removed
  • Removed deprecated wazuh-dbd daemon and database_output configuration. (#37035)
Fixed
  • Improved cluster payload buffer allocation strategy. (#37280)
  • Improved cluster archive decompression limits. (#37119)
  • Improved cluster worker file path validation. (#36998)
  • Improved API authentication stability with bounded thread pools, regex timeouts and payload size limits. (#37034)
  • Updated aiohttp, cryptography, PyJWT, python-multipart and starlette Python dependencies. (#37361)
Agent
Fixed
  • Fixed AWS SQS subscriber wodle resolving the wrong AWS account for cross-account iam_role_arn configurations. (#36791)
  • Fixed agent keepalive scheduling after a system clock rollback causing false Disconnected status. (#36338)
  • Fixed eBPF FIM whodata dropping file events on older kernels such as Amazon Linux 2 and 2023. (#37014)
  • Fixed eBPF FIM whodata missing file move/rename events into monitored folders. (#37023)
  • Added IP address validation to the ip-customblock active response to prevent malformed input in file path operations. (#36730)
  • Added a null check for inode and device fields in the FIM whodata event handler. (#37245)
Ruleset
Fixed
  • Fixed multiple Debian, Ubuntu and Windows SCA checks generating incorrect results. (#37385)
  • Fixed a typo in the SELinux SCA check causing false failures on CentOS 8, 9 and 10 systems configured as permissive. (#36361)
  • Fixed the AlmaLinux 9 and 10 bootloader permissions SCA check regex and optional file handling. (#36396)
  • Fixed the /etc/gshadow- permissions SCA check always failing due to an incorrect all condition. (#36795)
  • Fixed a macOS SCA PolicyBanner check false failure by wrapping the command in sh -c for glob expansion. (#36783)
RESTful API
Fixed
  • Fixed TypeError when sorting agents by version with empty version strings. (#37323)
  • Improved sensitive data masking in cluster configuration endpoint. (#37039)
View originalPermalink
How v4.14.7 went
v4.10.4

Wazuh v4.10.4

Added 1
  • Added detection of the -a never,task Audit rule in FIM whodata for Linux
Changed 5
  • Masked authd.pass in configuration API responses for users without update permissions
  • Changed sync primitive disposal to stop and soften teardown failures
  • Updated curl dependency to 8.12.1
  • Updated starlette dependency to 0.49.1
  • Upgraded Python embedded interpreter to 3.10.19
Fixed 6
  • Fixed analysisd plugin decoder argument alignment
  • Fixed admin protection in update user endpoint
  • Fixed protected settings checks when multiple ossec_config blocks are present
  • Improved cluster file synchronization path handling by adding safe path joins
  • Fixed Vulnerability Detector offset DB update to occur only after processing
  • Fixed Windows FIM Registry scan crash on non-null-terminated values
Security 4
  • Fixed path traversal in authd via agent group name validation
  • Hardened cluster deserialization by restricting callable decoding to Wazuh modules and improving error handling
  • Fixed DAPI callable resolution to restrict invocations to exposed resources only
  • Restricted cluster file transfer write paths
Manager
Changed
  • Masked authd.pass in configuration API responses for users without update permissions. (#34128)
Fixed
  • Fixed analysisd plugin decoder argument alignment. (#35222)
  • Fixed path traversal in authd via agent group name validation. (#35258)
  • Hardened cluster deserialization by restricting callable decoding to Wazuh modules and improving error handling. (#35256)
  • Fixed DAPI callable resolution to restrict invocations to exposed resources only. (#35256)
  • Fixed admin protection in update user endpoint. (#35469)
  • Fixed protected settings checks when multiple <ossec_config> blocks are present. (#34690)
  • Restricted cluster file transfer write paths. (#34659)
  • Improved cluster file synchronization path handling by adding safe path joins. (#35008)
  • Fixed Vulnerability Detector offset DB update to occur only after processing (backport from 4.12.0). (#31901)
Agent
Added
  • Added detection of the -a never,task Audit rule in FIM whodata for Linux. (#34661)
Changed
  • Changed sync primitive disposal to stop and soften teardown failures. (#34680)
Fixed
  • Fixed Windows FIM Registry scan crash on non-null-terminated values. (#34679)
Other
Changed
  • Updated curl dependency to 8.12.1. (#34687)
  • Updated starlette dependency to 0.49.1. (#33383)
  • Upgraded Python embedded interpreter to 3.10.19. (#32790)
View originalPermalink
How v4.10.4 went
v5.0.0-beta4Pre-release

Wazuh v5.0.0 Beta 4

Added 1
  • Add retry logic to indexer templates download
Changed 10
  • Suppress version-coordination WARNINGs on stop/unavailable module
  • Improve default cores detection
  • Upgrade 5.0.0 python dependencies
  • Change indexer user name and password
  • Close DBs on graceful shutdown, defer coordination during first sync, and increment SCA check version on change
  • Cache indexer credentials in clusterd
Fixed 8
  • Persist engine startup state for CMSync route logging
  • Fix invalid MTU value reported for Windows network interfaces
  • Restore modern.bpf.o checkfiles baseline reverted by 4.14.7 merge
  • Handle rootcheck removed tags
  • Improve fim_sync db performance
  • Fix version comparison in indexer documents updates
  • Propagate sync errors to each module
  • Fix server-side version bump for disconnected agent metadata updates
Removed 1
  • Remove startup deprecation warning from cluster_control and agent_upgrade
What's Changed

Full Changelog: https://github.com/wazuh/wazuh/compare/v5.0.0-beta3...v5.0.0-beta4

View originalPermalink
How v5.0.0-beta4 went
v4.14.6

Wazuh v4.14.6

Fixed 20
  • Improve message decompression handling in remoted
  • Improve agent name validation to reject names starting with dot
  • Fix segfault in vulnerability scanner module shutdown when disabled
  • Fix string buffer handling in version comparison function
  • Improve cluster file synchronization security
  • Improve cluster file synchronization error handling on invalid task identifiers
Removed 1
  • Remove unused SSL/TLS transport option from cluster
Manager
Removed
  • Removed unused SSL/TLS transport option from cluster. (#35648)
Fixed
  • Improved message decompression handling in remoted. (#35773)
  • Improved agent name validation to reject names starting with dot. (#35833)
  • Fixed segfault in vulnerability scanner module shutdown when disabled. (#36011)
  • Fixed string buffer handling in version comparison function. (#36059)
  • Improved cluster file synchronization security. (#36060)
  • Improved cluster file synchronization error handling on invalid task identifiers. (#36129)
  • Improved cluster merged file parameter validation to prevent directory escape. (#36204)
  • Improved tmp_file path validation in cluster DAPI. (#36246)
  • Improved cluster non-merged file path validation during worker file processing. (#36296)
  • Improved cluster node name format validation in the hello handler. (#36460)
  • Fixed missing agent.host.ip in inventory documents when agent IP is empty. (#35475)
  • Fixed stale agent synced status after hot reload on cluster worker nodes. (#6726)
Agent
Fixed
  • Fixed agent registration not running on reinstall after apt-get remove. (#35727)
  • Fixed MS-Graph integration handling for relationships containing /. (#35431)
  • Fixed macOS syscollector to skip package receipts whose payload is no longer installed. (#35380)
  • Fixed missing eBPF create, modify and delete events on Ubuntu 24/26 and improved FIM whodata healthcheck. (#35838)
  • Hardened FIM database path lookups by migrating to parameterized SQL queries. (#36399)
RESTful API
Fixed
  • Escaped control characters in API usernames in access logs. (#35866)
  • Added input validation in cluster result handling and authentication. (#35757)
  • Fixed current user resolution in the update-user endpoint to enforce admin protection. (#35442)
Ruleset
Fixed
  • Updated rootcheck trojan signatures to avoid false positives on modern distributions (Debian 13, Ubuntu 26, Arch Linux). (#35927)
Other
Changed
  • Updated cryptography, urllib3 and python-multipart Python dependencies. (#35982)
  • Updated eBPF libraries: libbpf to 1.7.0 and bpftool to 7.7.0. (#36467)
Fixed
  • Fixed wazuh-manager startup failure on RHEL 10 by dropping the libcrypt dependency from embedded Python. (#36782)
View originalPermalink
How v4.14.6 went
v5.0.0-beta3Pre-release

Wazuh v5.0.0 Beta 3

Added 1
  • Create a backup of local_rules.xml during execution of IT analysisd tier 0 1
Changed 12
  • Improve cluster file synchronization error handling
  • Update trojan signatures to avoid false positives on modern distros
  • Improve cluster merged file parameter validation
  • Improve tmp_file path validation in cluster DAPI
  • Serialize procps access to prevent modulesd crash
  • Propagate agent merged_sum after hot reload in cluster
Fixed 6
  • Restore working vulnerability scanner database workflow
  • Fix the wazuh-manager-modules crash that occurs while downloading the feed
  • Fix AlmaLinux 9/10 bootloader permissions SCA check regex and optional file handling
  • Treat the absence of the hash document as expected, not an error
  • Prevent Syscollector and SCA use-after-free on modulesd shutdown
  • Fix policy evaluation errors
Removed 1
  • Remove obsolete configuration blocks from API upload_configuration setting
What's Changed
New Contributors

Full Changelog: https://github.com/wazuh/wazuh/compare/v5.0.0-beta2...v5.0.0-beta3

View originalPermalink
How v5.0.0-beta3 went
v5.0.0-beta2Pre-release

Wazuh v5.0.0 Beta 2

Added 3
  • Add length validation after decompression in ReadSecMSG
  • Limit nested JSON depth in API requests
  • Add groups path validation
Changed 5
  • Improve buffer handling in regex match processing
  • Use daily marker for GuardDuty log collector
  • Upload size limit config mismatch implementation
  • Update embedded Python and dependencies
  • Update dependencies: cryptography, requests
Fixed 13
  • Dovecot decoders do not match correctly
  • CIS 35675 and 35689 rules bug
  • Empty-message failure in Windows enrollment integration test
  • Rate limit handling for /events endpoint
  • Escape document id in delete bulk operations
  • Uncontrolled memory allocation in cluster
What's Changed
New Contributors

Full Changelog: https://github.com/wazuh/wazuh/compare/v5.0.0-beta1...v5.0.0-beta2

View originalPermalink
How v5.0.0-beta2 went
v4.14.5

Wazuh v4.14.5

Changed 2
  • Changed RHEL init script with SUSE variant on SLES 11
  • Changed service check from WMI to sc.exe
Fixed 11
  • Fixed DAPI callable resolution to restrict invocations to exposed resources only
  • Fixed analysisd plugin decoder argument alignment
  • Fixed rootcheck false positive for /dev/.blkid.tab
  • Fixed ORDER_REVERSAL deadlocks in FIM
  • Fixed Roundcube decoder regex to prevent srcip truncation in Failed login logs
  • Fixed macOS Ventura SCA policy incorrectly passing pmset checks
Security 7
  • Fixed uncontrolled memory allocation in cluster caused by crafted packet length
  • Fixed rate limit bypass for the /events endpoint
  • Fixed buffer overflow in analysisd regex match processing
  • Fixed path traversal in authd via agent group name validation
  • Fixed size_t underflow in remoted ReadSecMSG causing potential heap overflow
  • Fixed RBAC bypass in DAPI allowing privilege escalation
  • Fixed heap buffer overflow in syscheck Registry Wildcard Expansion
Manager
Fixed
  • Fixed DAPI callable resolution to restrict invocations to exposed resources only. (#34889)
  • Fixed uncontrolled memory allocation in cluster caused by crafted packet length. (#35173) (#35412)
  • Fixed rate limit bypass for the /events endpoint. (#35077)
  • Fixed buffer overflow in analysisd regex match processing. (#35106)
  • Fixed path traversal in authd via agent group name validation. (#35230)
  • Fixed size_t underflow in remoted ReadSecMSG causing potential heap overflow. (#35193)
  • Fixed RBAC bypass in DAPI allowing privilege escalation. (#35307)
  • Fixed analysisd plugin decoder argument alignment. (#35176)
Agent
Fixed
  • Fixed rootcheck false positive for /dev/.blkid.tab. (#34734)
  • Fixed ORDER_REVERSAL deadlocks in FIM. (#34735)
  • Fixed Roundcube decoder regex to prevent srcip truncation in "Failed login ... in session" logs. (#34793)
  • Fixed macOS Ventura SCA policy incorrectly passing pmset checks. (#34693)
  • Fixed Office365 integration pagination by trimming HTTP header values. (#34673)
  • Fixed FIM false positives caused by double readdir check. (#34880)
  • Fixed audit log cache overflow for events with many records in logcollector. (#35285)
  • Fixed daily marker for GuardDuty log collector. (#35110)
  • Fixed rootcheck not generating findings. (#35297)
  • Fixed heap buffer overflow in syscheck Registry Wildcard Expansion. (#35287)
Changed
  • Changed RHEL init script with SUSE variant on SLES 11. (#34563)
  • Changed service check from WMI to sc.exe. (#34543)
  • Changed windows syscollector to include command arguments. (#34727)
RESTful API
Fixed
  • Fixed allow_higher_versions validation in API upload_configuration. (#34905)
  • Fixed nested JSON depth limit in API request processing. (#35224)
  • Fixed upload size limit config mismatch. (#35141)
Ruleset
Fixed
  • Fixed bug in CIS SCA checks 35675 and 35689 for Ubuntu 24.04. (#35088)
  • Fixed Dovecot decoders to correctly extract rip and lip fields. (#35089)
Other
Changed
  • Updated dependencies cryptography to 46.0.5, Werkzeug to 3.1.6, pip to 26.0.1 and wheel to 0.46.3. (#34907)
  • Updated embedded Python to 3.10.20 and dependencies pyjwt, pyasn1. (#35135)
  • Updated dependencies cryptography, requests. (#35331)
View originalPermalink
How v4.14.5 went
v5.0.0-beta1Pre-release

Wazuh v5.0.0-beta1

Added 6
  • Add cluster-by-default deployment model where all Wazuh Server installations run as a cluster node, removing the distinction between clustered and non-clustered deployments
  • Add stateless metadata enrichment in remoted, centralizing event metadata handling for stateless messages and removing the dependency on wazuh-db for that ingestion path
  • Add Engine enrichment support for IOC matching, GeoIP lookup, and event filters
  • Add Engine adaptation tier 2 with raw archives handling, uncategorized event routing, input-level throttling, and internal metrics exposure
  • Add Wazuh Instance Registration status to reflect CTI access_token availability with states Pending, Polling, Denied, and Available
  • Add local state persistence for agent modules including FIM, System Inventory, and SCA, removing the dependency on rsync with the Wazuh Server
Changed 10
  • Upgrade embedded Python interpreter from 3.10 to 3.12
  • Adapt Vulnerability Detector input pipeline to the new Wazuh 5.0 synchronization algorithm covering first-scan, inventory-change, and feed-update scenarios
  • Revamp Role-Based Access Control management and introduce an upgrade mechanism for existing RBAC configurations
  • Change the Wazuh Manager installation path to /var/wazuh-manager replacing /var/ossec and remove agent ID 000, fully decoupling agent and manager processes on shared hosts
  • Change Vulnerability Detection to use the Wazuh Indexer as the sole authoritative CVE data source, removing direct CTI network access from the agent-side Vulnerability Detector
  • Adjust agent-side Vulnerability Detector inventory emission and synchronization for OS, packages, and hotfixes to align with updated VD behavior in Wazuh 5.0
Removed 4
  • Remove Filebeat as the log-shipping component; event forwarding now uses native Wazuh server connectivity to the Wazuh Indexer via indexer-connector
  • Remove deprecated manager daemons: ossec-authd, wazuh-agentlessd, wazuh-maild, wazuh-dbd
  • Remove deprecated C CLI tools: manage_agents and agent-auth
  • Remove OpenSCAP server-side module
Manager
Added
  • Added cluster-by-default deployment model: all Wazuh Server installations now run as a cluster node, removing the distinction between clustered and non-clustered deployments. The cluster.disabled configuration option has been removed. (#31295)
  • Added stateless metadata enrichment in remoted, centralizing event metadata handling for stateless messages and removing the dependency on wazuh-db for that ingestion path. (#33269)
  • Added Engine enrichment support: IOC matching, GeoIP lookup, and event filters. (#33493)
  • Added Engine adaptation tier 2: raw archives handling, uncategorized event routing, input-level throttling, and internal metrics exposure. (#34477)
  • Added Wazuh Instance Registration status to reflect CTI access_token availability (Pending, Polling, Denied, Available), allowing the Dashboard to query the subscription state. (#31906)
Changed
  • Upgraded embedded Python interpreter from 3.10 to 3.12. (#33377) (#33570)
  • Adapted Vulnerability Detector input pipeline to the new Wazuh 5.0 synchronization algorithm, covering first-scan, inventory-change, and feed-update scenarios. (#30535)
  • Revamped Role-Based Access Control (RBAC) management and introduced an upgrade mechanism for existing RBAC configurations. (#27706)
  • Removed legacy configuration surfaces, database schemas, build targets, and compatibility layers in the second server cleanup phase. (#34608)
Removed
  • Removed Filebeat as the log-shipping component; event forwarding now uses native Wazuh server connectivity to the Wazuh Indexer via indexer-connector. (#33124)
  • Removed deprecated manager daemons: ossec-authd, wazuh-agentlessd, wazuh-maild, wazuh-dbd. (#30922)
  • Removed deprecated C CLI tools: manage_agents, agent-auth. (#30924)
  • Removed OpenSCAP server-side module. (#31028)
  • Removed inventory-related API endpoints. (#31299)
  • Removed legacy API security configuration endpoints. (#28425)
Fixed
  • Fixed Vulnerability Detector version matcher logic for improved detection accuracy. (#31746)
  • Fixed Cloudtrail log ingestion parsing errors. (#33108)
Agent
Added
  • Added local state persistence for agent modules (FIM, System Inventory, SCA), removing the dependency on rsync with the Wazuh Server and reducing network traffic and server-side processing overhead. (#29533) (#31838)
Changed
  • Changed the Wazuh Manager installation path to /var/wazuh-manager (replacing /var/ossec) and removed agent ID 000, fully decoupling agent and manager processes on shared hosts. (#33378)
  • Changed Vulnerability Detection to use the Wazuh Indexer as the sole authoritative CVE data source, removing direct CTI network access from the agent-side Vulnerability Detector. (#34849)
  • Adjusted agent-side Vulnerability Detector inventory emission and synchronization (OS, packages, hotfixes) to align with the updated VD behavior in Wazuh 5.0. (#33199)
  • Simplified rootcheck: removed the server-side database, sync path, and API surface; findings are now indexed through the standard alert pipeline. (#31478)
  • Updated logcollector file-tailing initial read strategy for more consistent behavior across log rotation scenarios. (#33382)
  • Updated Windows Event Channel log collection to emit native XML from EvtRender() without an XML declaration header. (#34462)
  • Increased default limits for agent event throughput and inventory message sizes. (#35330)
Removed
  • Removed deprecated agent binaries and legacy modules as part of the Wazuh 5.0 agent cleanup. (#30435)
  • Removed NSIS-based Windows agent installer; Windows agent now ships exclusively as an MSI package. (#31582)
Fixed
  • Fixed FIM checksum calculation that was incorrectly ignoring some file fields. (#29668)
  • Fixed syscollector reporting duplicate and bogus packages on macOS arm64. (#30513)
  • Fixed agent_control not displaying agent status information. (#32915)
  • Fixed SCA handling of invalid operators and missing values in regex patterns. (#35071)
  • Fixed agent modules initializing before agent metadata was fully ready. (#35156)
  • Fixed FIM inventory reporting file modification time as 1970-01-01. (#35162)
  • Fixed agent automatic reload failing after receiving centralized configuration. (#35169)
  • Fixed syscollector false positive package detection on macOS. (#35248)
View originalPermalink
How v5.0.0-beta1 went
v4.14.4

Wazuh v4.14.4

Changed 6
  • Updated Docker integration rules to improve detection coverage and compatibility
  • Changed msi_output extension from txt to log
  • Changed to unsigned char in print_hex_string
  • Changed sync primitive disposal to stop and soften teardown failures
  • Updated the azure-core dependency to 1.38.0 and the Werkzeug dependency to 3.1.5
  • Updated the protobuf dependency to 5.29.6 and the python-multipart dependency to 0.0.22
Fixed 12
  • Fixed heap-based null WRITE buffer underflows in the Manager
  • Fixed MS Graph default rules not triggering properly
  • Unified date formats in Active Response logs to ensure consistent timestamp formatting
  • Fixed heap-based NULL write buffer underflow in GetAlertData
  • Retained MSI installer log after Windows agent upgrade to improve troubleshooting visibility
  • Fixed incorrect Windows 11 edition detection after upgrading the agent to version 4.14.3
Manager
Fixed
  • Fixed heap-based null WRITE Buffer Underflows. (34658)
Agent
Fixed
  • Fixed MS Graph default rules not triggering properly. (#34240)
  • Unified date formats in Active Response logs to ensure consistent timestamp formatting. (#34473)
  • Updated Docker integration rules to improve detection coverage and compatibility. (#34376)
  • Fixed heap-based NULL write buffer underflow in GetAlertData. (#34501)
  • Retained MSI installer log after Windows agent upgrade to improve troubleshooting visibility. (#34517)
  • Fixed incorrect Windows 11 edition detection after upgrading the agent to version 4.14.3. (#34530)
  • Fixed macOS agent crash during syscollector reload caused by invalid pthread_cond_destroy() usage. (#34274)
  • Fixed Windows OS edition detection. (34540)
  • Fix pthread_mutex_destroy invalid argument error on AIX in syscollector. (#34900)
Changed
  • Changed msi_output extension from txt to log. (34541)
  • Changed to unsigned char in print_hex_string. (34602)
  • Changed sync primitive disposal to stop and soften teardown failures. (34552)
RESTful API
Fixed
  • Fixed timestamps in the /agents/upgrade_result endpoint to return accurate UTC time. (#34176)
  • Improved cluster file synchronization path handling by adding safe path joins. (#34464)
  • Fixed API login race condition- (34459)
Other
Changed
  • Updated the azure-core dependency to 1.38.0 and the Werkzeug dependency to 3.1.5. (#34154)
  • Updated the protobuf dependency to 5.29.6 and the python-multipart dependency to 0.0.22. (#34403)
View originalPermalink
How v4.14.4 went
v4.14.3

Wazuh v4.14.3

Added 2
  • Add hostname and architecture metadata to Windows keep-alive messages
  • Add CIS SCA policy for macOS 26 Tahoe
Changed 1
  • Improve authentication performance by caching generated keypairs and clearing the cache when key files change
Fixed 13
  • Escape document ID when necessary before sending document to indexer
  • Extend timestamp conversion helpers to support additional input formats and normalize ISO8601 strings
  • Fix memory leak in the CIS-CAT decoder when database operations fail
  • Fix ruleset hot reload on workers by awaiting send_reload_ruleset_msg
  • Fix UTF-16 casting when updating report_changes
  • Improve Active Response key handling in wazuh-execd
Security 7
  • Restrict cluster file transfer write paths
  • Harden cluster deserialization by restricting callable decoding to Wazuh modules and improving error handling
  • Add query size checks for syscollector delta sync SQL generation to prevent buffer overflows
  • Replace unsafe sprintf calls in the SCA decoder to prevent buffer overflows
  • Add bounds checking to Logcollector max-size configuration serialization
  • Harden Logcollector multiline backup handling to use full-buffer copies
  • Extend Windows network path restrictions to block extended-length UNC paths
Manager
Fixed
  • Scaped document ID when necessary before sending document to indexer. (#33464)
  • Extended timestamp conversion helpers to support additional input formats and normalize ISO8601 strings. (#33551)
  • Restricted cluster file transfer write paths. (#33705)
  • Hardened cluster deserialization by restricting callable decoding to Wazuh modules and improving error handling. (#33910)
  • Added query size checks for syscollector delta sync SQL generation to prevent buffer overflows. (#33803)
  • Replaced unsafe sprintf calls in the SCA decoder to prevent buffer overflows. (#33756)
  • Fixed a memory leak in the CIS-CAT decoder when database operations fail. (#33739)
  • Fixed ruleset hot reload on workers by awaiting send_reload_ruleset_msg. (#34184)
Agent
Added
  • Added hostname and architecture metadata to Windows keep-alive messages. (#33831)
Fixed
  • Fixed UTF-16 casting when updating report_changes. (#33495)
  • Improved Active Response key handling in wazuh-execd. (#33665)
  • Added bounds checking to Logcollector max-size configuration serialization. (#33704)
  • Hardened Logcollector multiline backup handling to use full-buffer copies. (#33926)
  • Fixed label formatting edge cases in keep-alive notify messages. (#33708)
  • Fixed a false positive in vulnerability detection for Oracle Linux 8. (#33583)
  • Extended Windows network path restrictions to block extended-length UNC paths. (#34115)
  • Fixed crash in network path detection on Windows. (#34162)
  • Fixed Agent reload failure on Linux systems with systemd version 219 or lower. (#34064)
RESTful API
Changed
  • Improved authentication performance by caching generated keypairs and clearing the cache when key files change. (#33702)
Fixed
  • Improved configuration upload validation by parsing and comparing Wazuh XML configurations more reliably. (#33683)
  • Fixed protected settings checks when multiple <ossec_config> blocks are present. (#33807)
Ruleset
Added
  • Added a CIS SCA policy for macOS 26 Tahoe. (#33492)
Fixed
  • Fixed SCA policy execution on Windows Server 2019 by using the correct PowerShell path. (#34141)
Other
Changed
  • Updated the werkzeug dependency to 3.1.4. (#33569)
  • Updated the urllib3 dependency to 2.6.3. (#33927)
View originalPermalink
How v4.14.3 went
View all

Discussion