Releases: wallarm/sidecar
Releases · wallarm/sidecar
helm-chart-5.3.9
- Bump Sidecar Controller version to 1.6.1
- Fix controller vulnerabilities CVE-2025-26519, CVE-2024-12797 and CVE-2024-13176
helm-chart-5.3.8
- Fix vulnerabilities CVE-2025-26519 and CVE-2024-12797
helm-chart-5.3.7
- Fix for INVALID_XML attack detection in responses
- Fix controller vulnerabilities CVE-2025-0665 and CVE-2025-0725
- Minor GraphQL parser fixes
helm-chart-5.3.0
- Added support for response parameters in API Sessions for providing the full context of user activities and more precise session grouping
- Added a full-fledged GraphQL parser that allows:
- Improved detection of the input validation attacks in GraphQL-specific request points
- Fine-tuning attack detection for specific GraphQL points (e.g., disable detection of specific attack types in specific points)
- Analyzing specific parts of GraphQL requests in API sessions
- Fixed invalid time value in serialized requests to properly display the resource overlimit attacks
- Added configurable parameters for API FW in Helm chart values
- Added configurable parameter for NGINX extended logging in Helm chart values
helm-chart-5.2.11
- [APIFW] Version bumped to v0.8.6
- [WCLI] Minor bug fixes
- Fixed vulnerabilities: CVE-2024-45337, CVE-2024-45338
helm-chart-5.2.1
New $wallarm_attack_point_list and $wallarm_attack_stamp_list variables for extended logging
These variables log parameters containing malicious payloads and attack sign IDs enabling advanced debugging of Node behavior.
Minor bug fixes
helm-chart-5.1.0
- Over-limit events improvements
- Bumped APIFW version to 0.8.3
- wallarm_attack_type / wallarm_attack_type_list NGINX variables now properly show APIFW attacks
- [init container]Reduced memory usage during node registration
helm-chart-4.10.13
- Fixed memory leak on duplicate response headers in libproton (initially introduced in 4.8)
- Fixed memory leak in libwacl on IP addresses that are not in acldb but have known source (initially introduced in 4.8)
- Backported API Discovery fix of errors on missing status code
helm-chart-5.0.3
- Added support for customizing sensitive data detection in API Discovery
- Fixed memory leak on duplicate response headers in libproton
- Fixed memory leak related to IP addresses that are not in IP lists but have known source
helm-chart-5.0.2
- fixed installation fails without AAS subscription
- fixed export attack delay metric