# 2.9.0 pfSense CE software release * Bug #16153: ECL can modify a discovered config file * Bug #16769: Interfaces Status shows an invalid SSID value for Wi-Fi interfaces * Bug #16861: Static route not removed when enabling ``dpinger_dont_add_static_route`` while a gateway monitor IP address is set * Regression #16768: pkg 2.6.2 breaks the GUI update check code * Bug #16906: Unbound configuration may be generated with duplicate interface bindings * Todo #16636: Remove ``quick`` from previous ``match`` rules on upgrade * Bug #16637: Unbound configuration validation does not test the complete configuration * Todo #16471: Upgrade PHP to 8.4 * Bug #16472: Cannot set RADVD router lifetime to ``0`` * Bug #16475: Filter rule evaluation continues after matching a ``match quick`` rule * Feature #12495: Preserve other record types when updating IPv4 or IPv6 using deSEC DDNS * Todo #16905: Encode Dynamic DNS credentials when passed as URL parameters * Bug #16339: Captive Portal ``backwardsyncpassword`` value not sanitized in status output * Feature #13340: Option to change QinQ ethertype to Service VLAN Tag * Bug #16505: Korean locale configuration name is incorrect * Feature #16613: Allow using interface subnet macros with interfaces which only contain VIPs * Bug #16923: Potential XSS via inline Firewall Log rule descriptions * Bug #15087: IPsec Keep Alive does not update the gateway status * Todo #16559: Remove custom gateway ordering * Bug #16924: Potential stored XSS via Firewall Schedules * Bug #16925: IPv6 Track Interfaces ignores the ``Disabled`` Router Advertisements mode * Bug #16557: Alerts do not trigger for empty configuration change descriptions * Feature #16615: Omit NAT64 address for queries from the firewall itself * Bug #16922: Captive Portal authentication failures from usernames containing special characters or long strings can cause ambiguous or confusing log messages * Feature #16616: Option to set a default log level for all logs * Feature #15221: Sort list of System Tunables * Todo #16551: Update output and parsing behavior for PHP shell ``pfanchordrill`` * Bug #16552: Hostnames in Kea static leases may not be registered with DNS * Bug #16941: Potential XSS in DHCPv6 Pool Descriptions * Bug #16942: Potential XSS via IPsec Phase 1 descriptions while editing Phase 2 entries * Todo #16118: Increase amount of system alias content printed in alias list * Bug #16944: Potential XSS in Dynamic DNS widget display of Custom and RFC2136 entries * Bug #16428: OpenVPN does not include ``client-to-client`` in generated configuration for Peer-to-Peer SSL/TLS servers * Bug #16947: Potential Local File Include vulnerability via Dashboard widget sequence data * Regression #16368: Custom Dynamic DNS services ignore the monitor interface * Bug #16312: ``sshguard`` does not trigger for GUI logins from usernames containing unexpected characters * Regression #16313: sshguard patch files are not present in devel branches * Bug #15346: Cannot add Port Forward with an unassociated filter rule * Bug #16549: Captive Portal "Allowed IPs" entries do not work if the language is not set to English * Bug #16954: Filter rules created as part of NAT rules can have an invalid protocol value * Todo #16432: Allow assigning bridge members which have an IP address * Feature #16624: Allow packages to preserve RAM disk data between boots * Bug #16625: Input validation error when saving an existing static route which contains an alias destination * Feature #16215: Allow floating rules using the "match" action to match based on IP Options * Bug #16634: Some package installation configuration data may be missing after OS upgrade * Feature #16635: Gateway recovery functionality for the default failover gateway group when all gateways are offline * Bug #16899: Potential command execution via CR/LF in OpenVPN settings * Bug #16566: Incorrect configuration change message when deleting an outbound NAT rule * Bug #16927: Multiple ``updaterrd.sh`` processes * Todo #16958: Improve handling of OpenSSL encryption passphrase * Todo #16959: Add ``device_key`` to filtered tags list for status output * Bug #16218: All-Inkl Dynamic DNS responses are not parsed correctly * Todo #16961: "Wake All" functionality on ``services_wol.php`` should only use POST * Feature #16960: Kea Custom Configuration JSON privilege * Bug #16141: RRD data fails to restore via the ECL * Bug #16142: XMLRPC requests fail due to incorrect request path * Bug #16964: URL tables cannot import content from ``tgz`` file URLs * Bug #16945: Potential XSS via URL Table Ports Alias content * Bug #16266: Thermal Sensors widget does not respect per-sensor threshold vales * Regression #16575: Firewall logs do not match PF rules with rule number ``0`` * Regression #16449: e1000 network interfaces unexpectedly link at half-duplex * Regression #16638: PPPoE on VirtIO ``vtnet`` interface fails to pass routed traffic * Feature #16325: Add support for labels in configuration rules * Bug #16579: Firewall logs do not correctly parse ``short`` packet errors * Bug #16979: Traffic Graphs display option "Description" does not utilize DHCP static mapping descriptions * Bug #16322: Gateway monitoring daemon can unexpectedly use a CARP VIP as the source IP address * Todo #16580: Require absolute path when saving a file on ``diag_edit.php`` * Regression #16330: Changing a firewall rule protocol always toggles the display of advanced option * Feature #16230: Option to control Kea log level * Regression #16326: Dynamic DNS does not use preferred VIP in Gateway Group * Bug #16644: Firewall log always shows rules with Reject action under "Associated Rules" * Feature #16166: Option to deactivate ALTQ for VirtIO ``vtnet`` interfaces * Bug #16588: ``pfctl`` shows incorrect number of table addresses * Bug #16376: Some remote syslog messages are duplicated when "System Events" option is enabled * Regression #16362: ``syslogd`` daemon can terminate when a remote log server refuses connections * Todo #16469: Improve file handling of the configuration cache * Feature #15952: PHP RADIUS client ``Message-Authenticator`` attribute capability * Bug #16770: Potential XSS in RSS Widget feed content post titles * Bug #16264: Captive Portal Ethernet rules can block ARP * Todo #16538: Prevent the GUI from removing vital packages * Bug #16272: Input validation text for deleting an IP Alias VIP within a CARP VIP subnet may reference incorrect VIP * Bug #15411: Log entries without a hostname can cause the system log to display in an unexpected manner * Regression #16243: PPPoE MSSFix uses incorrect values for 6RD * Regression #16232: Swap fails to activate when multiple swap partitions exist * Todo #16307: Refactor PF ruleset generation * Bug #15770: Using a Limiter on a rule with a gateway group limits all traffic through that gateway instead of the host IP address * Bug #16901: Daemon configuration manipulation via CR/LF in SNMP settings * Todo #16291: Relocate Kea control socket and lease database * Bug #16898: Potential command execution via CR/LF in System Proxy settings * Todo #16388: Upgrade to Kea 3.0.2 * Feature #16068: Option to disable logging of packets blocked due to unmatched IP options * Bug #16248: QLink/Marvell 41000 NIC bug * Bug #16351: Automatic IPv6 gateways for OpenVPN servers are created with the wrong gateway address * Bug #16216: PPPoE interfaces using ``if_pppoe`` increase error counters due to normal ALTQ traffic shaping operations * Feature #16241: Block non-global NAT64 addresses by default * Regression #16451: CE shows QAT as a crypto option * Bug #16341: Error notification and log message ``"Updating repositories metadata" returned error code 1`` at boot due to ``certctl`` race condition * Regression #13622: Retain previous QinQ VLAN tag type value for existing entries on upgrade * Bug #16487: Virtual IP addresses on PPPoE interfaces using ``if_pppoe`` can prevent PPP session termination * Todo #16515: Set appropriate log levels for PHP and ``/usr/bin/logger`` logs * Regression #16513: WireGuard service show status stopped but peers can still connect * Bug #16456: Memory leak in ``libpfctl`` causes ``bsnmpd`` memory usage to grow over time * Feature #16517: Endpoint-independent Port Restricted Cone Outbound NAT rules * Regression #16407: Editing an alias used in static routes does not correctly update the routing table * Todo #16468: Kea configuration parameter ``client-class`` is deprecated * Bug #16763: Potential Stored XSS in ``diag_arp.php`` when using ISC DHCP * Feature #16029: Add option to search for LDAP groups in the base DN * Todo #16653: Add label to automatic PF ``antispoof``, CARP, Captive Portal, and ICMPv6 rules * Bug #16690: Dynamic DNS client ignores Verify SSL/TLS Certificate Trust option when the entry does not contain a username * Bug #14741: PHP error in DNS Forwarder host overrides when the language is set to French * Bug #16654: Interfaces menu does not use natural sorting when configured to sort alphabetically * Regression #16421: OpenVPN servers will not start with DH parameter lengths less than 2048 * Todo #16503: Update Unbound to 1.24.2 to address CVE-2025-11411 * Feature #16502: Support state killing on gateway recovery for policy-routed traffic from the firewall itself * Feature #16534: Omit reserved NAT64 addresses from DNS64 answers * Regression #16682: ``daemon`` facility messages are not logged * Bug #16681: Inaccurate "No default gateway found" log message when the default gateway is set to automatic * Feature #16253: Fix configuration artifacts on upgrade * Regression #16528: ``sshguard`` does not trigger for GUI auth failures due to log format changes * Bug #16900: Daemon configuration manipulation via CR/LF in ISC DHCP settings * Bug #16495: Gateway list order is incorrect until reloading page after moving entries and saving * Todo #16509: Update strongSwan to 6.0.3 * Bug #16943: Potential XSS in PPP instance Provider and Plan fields * Todo #6727: Apple TouchID/FaceID probes for site icon files that do not exist * Feature #16308: Avoid traffic stalls from unnecessary filter reloads * Bug #16962: Daemon configuration manipulation via CR/LF in ISC DHCP numbered option settings * Feature #16695: Include System Patches package by default * Feature #16914: Set IP Alias VIP as the Router Advertisement source * Todo #16128: Sanitize PPPoE configuration parameters * Bug #16546: NAT64 rules do not pass traffic when a gateway is specified for the rule * Todo #16816: Improve default gateway detection when gateways share the same address * Bug #16540: Reserved DUMMYNET pipes for Captive Portal can overlap * Bug #16429: NAT64 rules using ``reply-to`` do not forward packets * Bug #15017: DHCP relay does not respect configured CARP VIP status * Todo #16567: Do not add ``fe80::1:1`` link-local address to interfaces configured for IPv6 tracking * Regression #16697: Kea DHCPv6 Leases page does not include delegated prefixes from active dynamic leases * Bug #16976: Potential XSS in Traffic Graphs Display option * Bug #16940: Potential XSS in DHCPv4 Pool Descriptions * Bug #16918: Potential stored XSS in ``browser.php`` used by ``diag_edit.php`` * Bug #16314: GUI login events from usernames containing special characters or long strings can cause ambiguous or confusing log messages * Bug #16550: Cannot load alternate TCP Congestion Control kernel modules * Bug #16709: Cannot disable IPsec Advanced Settings tab option for Strict Interface Binding * Todo #16620: Remove dead link about ``.local`` TLD use from ``system.php`` * Todo #16626: Save the update branch preference on system update * Bug #16602: ``kea2unbound`` crashes when reading an invalid configuration file * Bug #16593: Potential remote command execution via DNSSL router advertisement messages * Bug #16610: GUI does not prevent adding a VIP with a blank address * Todo #16707: Improve gateway status consistency * Feature #16423: Update the SSH server configuration to current standards and include post-quantum cryptography algorithms * Todo #16657: Improve handling of certificates without subjects * Bug #16614: Connections from the firewall itself fail with oversize packets and TSO enabled * Bug #16630: Inconsistent and incorrect privilege names on some PPP service-related log tabs * Todo #16606: Update recommended maximum server certificate lifetimes to 200 days * Feature #16666: Allow wildcard records for Dynamic DNS provider deSEC.io * Bug #16724: RAM disk package data is not preserved for additional packages * Bug #16721: Creating a new user ignores certificate checkbox value if the certificate fields are populated * Bug #16783: Same port forward on multiple WANs can generate a PF error due to Pure NAT mode NAT reflection * Bug #16720: GUI performance degradation due to check for weak passwords on each page load * Bug #16784: Error updating repository metadata at boot with certain packages installed * Todo #16747: Remove user survey prompts * Todo #16658: Automatically configure the OpenVPN tunnel MTU when set in the assigned interface configuration * Bug #16661: UTF-8 characters in configuration data can result in an invalid configuration * Todo #15780: Speed up MBUF Usage command in System Information Dashboard widget * Bug #16836: IPsec daemon can crash if a peer initiates two rekeys for the same child SA * Regression #16672: Firewall rules matching and tagging across distinct anchors are ignored by subsequent tagged rule * Bug #16773: Potential XSS in Captive Portal widget * Bug #16726: Loader menu does not display the logo properly * Bug #16743: ``isvalidpid()`` function does not properly check or escape PID file parameter * Regression #16815: All OpenVPN instances are restarted when applying changes to any assigned interface * Bug #16290: ``diag_authentication.php`` crashes with a core dump if RADIUS client Shared Secret value is not correct * Bug #16731: Cannot update GoDaddy Dynamic DNS AAAA record * Regression #16733: RSS widget generates a PHP error with custom feed * Bug #16729: Firewall rule source option ``This Firewall (self)`` is not available when duplicating floating rules * Todo #16826: Exclude nginx logs from ``system.log`` * Regression #16728: Changing the password from the default in the GUI from the default requires a logout and login to continue * Bug #16744: Potential XSS in Delegated Length value for Prefix Delegation on ``services_dhcpv6.php`` when using Kea * Todo #16793: Improve GUI handling of user aliases that are automatically managed by the system * Regression #16688: Creating a CA certificate with Trust Store checked is not trusted * Todo #16745: Migrate ``config.xml`` encoding from ENT_HTML401 to ENT_XML1 * Regression #16795: Automatically generated ``vpn_networks`` table is missing OpenVPN networks * Bug #16799: LDAP shell authentication does not honor configured group DN restriction * Feature #16706: 6rd interface prefix tracking for OpenVPN IPv6 tunnel network * Bug #16705: Automatic gateways for OpenVPN peer-to-peer servers with a ``/30`` tunnel network do not use the peer address * Todo #16605: Update certificate expiration warning behavior * Feature #16607: Auto-renewal for certificates * Feature #16819: Log errors when determining the RFC2136 update source address * Regression #16803: Links to send WOL packets are not handled consistently, may fail to send * Todo #16796: Retain a copy of the failed ruleset when a filter reload fails * Regression #16790: Kernel panic due to race condition on a ``bpf`` device * Bug #16719: DHCP clients may not receive the reserved address after changing the DHCP static mapping * Regression #16825: Shared Key OpenVPN tunnels need directive to bypass deprecation error * Bug #16771: NULL bytes in an IP address can trigger PHP errors from ``ip2long()`` * Bug #16828: Kernel panic (page fault) in ``bpfmtap`` via ``vlantransmit`` with Suricata BPF listeners active on VLAN interfaces * Todo #16865: Kea attempts DNS Registration when Unbound is disabled * Todo #16882: Update dpinger to version 3.6 * Todo #16792: Improve GUI handling of user rules that are automatically managed by the system * Regression #16863: RADIUS authentication fails when attribute contains an invalid ACL * Regression #16866: Traffic Shaper Wizard duplicates all firewall rules when no shaping options are enabled * Bug #11797: Traffic Totals lost upon reboot when using a ramdisk for /var and /tmp * Bug #14491: FRR not starting with AgentX enabled * Bug #15916: pfBlockerNG dnsbl daemon not able to start in CARP mode * Bug #15274: HAProxy Configuration Changes Require pfSense Reboot to Take Effect * Bug #16220: WireGuard dashboard widget default refresh interval is invalid * Todo #16969: Update mdns-bridge to version 3.0.0 * Bug #16211: Python errors in Cellular * Bug #16225: Telegraf service does not restart after change of settings * Feature #16970: Update mDNS-Bridge package to 3.0 * Feature #16576: update nmap package to 7.99_1 * Bug #15909: Prevent tailscale interface from being assignable * Todo #16231: Update packages to use the XMLRPC plugins for HA * Feature #16070: Add ANDwatch package * Feature #16089: Add Zabbix 7.4 * Todo #16399: Update mDNS-Bridge to 2.2 * Regression #16518: net-mgmt/pfSense-pkg-arpwatch: sendmail_proxy.php missing dot between hostname and domain * Bug #16348: HAProxy configuration references non-existent certificate files * Feature #16533: Add Multicast Bridge (mcast-bridge) package * Bug #16756: Editing a Firewall Rule before Forcing pfBlockerNG Update Empties All Aliases * Regression #16785: STunnel Core Dumps when started * Todo #16883: Update mcast-bridge to version 1.5.0 * Todo #16884: Update mdns-bridge to version 2.6.0