DH20.01 release register
51 verified CSF/LFD bug and exploit fixes in DH20.01
The public register documents every hardening requirement shipped in signed release DH20.01. Three operational controls bring the complete qualification matrix to 54 of 54 verified gates.
DCSF
Every security remediation in the signed release
The register covers command boundaries, parsers, files, remote sources, panels, clusters, processes, DNS and firewall state. Statuses are bound to the published package.
51All
51Implemented
51Verified
- P-01
Isolate Messenger reCAPTCHA input from every root shell boundary
Verified - P-02
Keep remote GLOBAL feeds data-only and unable to deliver advanced rules
Verified - P-03
Protect Messenger files from symlink, hardlink and replacement races
Verified - P-04
Parse CIDR /0 explicitly and permit it only through caller policy
Verified - P-05
Require pinned RSA-3072 signatures, SHA-256-bound metadata and rollback checks for updates
Verified - P-06
Harden the DirectAdmin privileged bridge and verify identity transitions
Verified - P-07
Run privileged Perl entry points in taint mode with a minimal environment
Verified - P-08
Generate a protected host-local key for the standalone interface
Verified - P-09
Bound standalone UI workers, requests, searches, pre-authentication time and emitted output
Verified - P-10
Add CSPRNG sessions, CSRF protection, secure headers and modern TLS to the standalone UI
Verified - P-11
Encode untrusted output at the final rendering boundary in every UI adapter
Verified - P-12
Classify Dovecot 2.4 success and failure variants without known false positives
Verified - P-13
Ignore managesieve-login consistently in every applicable profile
Verified - P-14
Restrict custom regex results to validated TCP or UDP ports from 1 to 65535
Verified - P-15
Enforce HTTPS with certificate and hostname verification for remote sources
Verified - P-16
Validate download status, size and format before atomic last-good replacement
Verified - P-17
Propagate restore failures and retain the last working firewall state
Verified - P-18
Extract ZIP blocklists with strict limits and atomic replacement
Verified - P-19
Bound log records before regex processing and remove catastrophic patterns
Verified - P-20
Authenticate, frame and resource-bound all cluster traffic
Verified - P-21
Isolate LF_DIRWATCH offenders and recover monitoring automatically
Verified - P-22
Apply LF_SCRIPT_PERM changes only to the verified open inode
Verified - P-23
Keep secrets out of arguments, URLs, unsafe files and diagnostic bodies
Verified - P-24
Use one strict canonical API for IPv4, IPv6 and CIDR normalization
Verified - P-25
Validate the final mail envelope and invoke sendmail without a shell
Verified - P-26
Resolve exact syslog user names, including names beginning with an underscore
Verified - P-27
Separate display DNS data from security-authorisation cache state
Verified - P-28
Match trusted hostnames only as exact names or DNS-label suffixes
Verified - P-29
Canonicalise PTR data before cache, logs, mail, HTML or configuration use
Verified - P-30
Bound DNS verification and caches by time, concurrency, size and complexity
Verified - P-31
Allow privileged CyberPanel mutations only through protected POST actions
Verified - P-32
Remove predictable and followable temporary files from every installer
Verified - P-33
Prevent raw-byte record readers from splitting inside multibyte characters
Verified - P-34
Register, authorise and bound every persistent store consumed by root
Verified - P-35
Use one unambiguous transactional grammar for temporary firewall rules
Verified - P-36
Render alert templates once and prevent untrusted MIME structure injection
Verified - P-37
Drop Messenger v1 privileges irreversibly and close inherited descriptors
Verified - P-38
Contain Messenger v2 and v3 webroots and generated webserver configuration
Verified - P-39
Verify the Messenger identity and make each instance lifecycle transactional
Verified - P-40
Build and install releases from a closed, verified artifact inventory
Verified - P-41
Transport authenticated panel requests without invoking a shell
Verified - P-42
Validate and install remote Geo and ASN datasets as one last-good transaction
Verified - P-43
Bound log-record allocation before a complete attacker-controlled line enters memory
Verified - P-44
Bind process actions to kernel identity rather than a reusable PID or socket inode
Verified - P-45
Ensure fork-bomb handling never treats a session ID as a process-group ID
Verified - P-46
Remove command text and custom pignore regexes as process identity or action authority
Verified - P-47
Prevent attacker-controlled comm bytes from shifting procfs identity fields or hiding a process
Verified - P-48
Prevent executable exceptions from bypassing accounting across UID, service or supervisor boundaries
Verified - P-49
Bound procfs scanning per object, per UID and globally with cross-UID fairness
Verified - P-50
Bound lock-hang recovery and never signal a target parsed from lock-file bytes
Verified - P-51
Block secondary InterWorx NodeWorx accounts from DCSF unless they hold native firewall authority
Verified
DCSF
Three operational release controls
Beyond the 51 remediations, the matrix covers installation profiles, CC_DENY reply handling and Docker policy preservation. All three controls are verified.
Preserve replies to locally initiated connections under CC_DENY without admitting new inbound traffic
VerifiedPreserve Docker-owned chains and DOCKER-USER policy through firewall restart and rollback
VerifiedReleased
Download releaseAll 51 security fixes are verified
The complete DH20.01 matrix passed 54 of 54 release gates. The signed DCSF 15.10.4 package is publicly available.