← Back to all sparks
A

AdGuard Home

INFRA · APIS
Velocity5.0

Self-hosted network-wide ad and tracker blocking DNS server

AdGuard Home patches a DNS-over-QUIC resource exhaustion advisory and moves edge to the new UI

dnsad-blockingsecuritydns-over-quicself-hosted
Current state
v0.107.79 is presented as a stability release but carries the security work: a Go update for the vulnerabilities fixed in 1.26.6 and hardening against resource exhaustion over DNS-over-QUIC, published as GHSA-w6v6-f44j-3rj2. Alongside it, bootstrap server config accepts comments, install APIs gain a language property, static lease hostnames can be removed over HTTP, strict_sni_check is deprecated, and DNS64 stops treating unresolved CNAME/DNAME answers as the end of the chain.
Where it's heading
Two channels run in parallel — the 0.107 stable line and the 0.108 beta — and the edge channel has now switched to the new UI and versioning scheme, which is the first concrete sign that the 0.108 work is being staged for release. Stable releases keep absorbing protocol correctness fixes and DNS-over-QUIC hardening.
Prediction
With edge already on the new UI and versioning scheme, the 0.108 line is the likely destination for that switch, and strict_sni_check being deprecated now points to its removal there.

Recent moves

  1. 16h ago

    AdGuard Home 0.107.79 hardens DNS-over-QUIC against resource exhaustion

    Framed as a stability release, but it carries a DNS-over-QUIC resource exhaustion advisory and a Go security update. The edge channel switching to the new UI and versioning scheme is the more forward-looking item buried in it.

    View source ↗
  2. 19d ago

    Beta b.90 carries the DNS-over-QUIC exhaustion fix

    A beta on the 0.108 line, where the new UI work has been accumulating ahead of the edge channel switch.

    View source ↗
  3. 1mo ago

    Beta b.89 hardens against JIGGLE attacks (GHSA-p5f5-3p5g-rfjw)

    An earlier 0.108 beta, part of the parallel development track running alongside stable.

    View source ↗
  4. 1mo ago

    0.107.78: over half the changelog is security fixes

    The previous stable release, following the same pattern of correctness fixes on the 0.107 line.

    View source ↗
  5. 2mo ago

    Beta b.88 patches path traversal in GLiNET auth (CVE-2026-41448)

    A small beta cut on the 0.108 line with limited notes.

    View source ↗
  6. 2mo ago

    0.107.77 patches a community-reported vulnerability

    An earlier stable release in the same maintenance rhythm.

    View source ↗