[
  {
    "artifact_id": "nginx-node",
    "version": "6.12.7",
    "line": "6.x",
    "date": "2026-06-26",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6127-2026-06-26",
    "body_markdown": "#### All-in-one installer\n\n* Added support for the latest Ubuntu, Alpine, and Oracle Linux distribution NGINX packages\n* Added the [`wallarm_enable_mcp_global`](../admin-en/configure-parameters-en.md#wallarm_enable_mcp_global) directive to enable or disable downloading MCP rules and schemas from the Wallarm Cloud (enabled by default)\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added the [`wallarm_enable_mcp_global`](../admin-en/configure-parameters-en.md#wallarm_enable_mcp_global) directive to enable or disable downloading MCP rules and schemas from the Wallarm Cloud (enabled by default)\n\n#### Helm chart for Sidecar\n\n* Added the [`wallarm_enable_mcp_global`](../admin-en/configure-parameters-en.md#wallarm_enable_mcp_global) directive to enable or disable downloading MCP rules and schemas from the Wallarm Cloud (enabled by default)\n\n#### NGINX-based Docker image\n\n* Added the [`wallarm_enable_mcp_global`](../admin-en/configure-parameters-en.md#wallarm_enable_mcp_global) directive to enable or disable downloading MCP rules and schemas from the Wallarm Cloud (enabled by default)\n\n#### Amazon Machine Image (AMI)\n\n* Added the [`wallarm_enable_mcp_global`](../admin-en/configure-parameters-en.md#wallarm_enable_mcp_global) directive to enable or disable downloading MCP rules and schemas from the Wallarm Cloud (enabled by default)"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.12.6",
    "line": "6.x",
    "date": "2026-06-22",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6126-2026-06-22",
    "body_markdown": "#### All-in-one installer\n\n* Added support for NGINX stable 1.30.3\n* Added support for NGINX mainline 1.31.2\n* Improved [MCP (Model Context Protocol)](../api-discovery/exploring.md#mcp-servers) traffic analysis logging — the Node no longer produces excessive log output when there is no MCP traffic\n* Fixed the [CVE-2026-39821](https://nvd.nist.gov/vuln/detail/CVE-2026-39821) vulnerability in [API Specification Enforcement](../api-specification-enforcement/overview.md)\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Improved [MCP (Model Context Protocol)](../api-discovery/exploring.md#mcp-servers) traffic analysis logging — the Node no longer produces excessive log output when there is no MCP traffic\n* Fixed the [CVE-2026-39821](https://nvd.nist.gov/vuln/detail/CVE-2026-39821) vulnerability in [API Specification Enforcement](../api-specification-enforcement/overview.md)\n\n#### Helm chart for Sidecar\n\n* Improved [MCP (Model Context Protocol)](../api-discovery/exploring.md#mcp-servers) traffic analysis logging — the Node no longer produces excessive log output when there is no MCP traffic\n* Fixed the [CVE-2026-39821](https://nvd.nist.gov/vuln/detail/CVE-2026-39821) vulnerability in [API Specification Enforcement](../api-specification-enforcement/overview.md)\n\n#### NGINX-based Docker image\n\n* Improved [MCP (Model Context Protocol)](../api-discovery/exploring.md#mcp-servers) traffic analysis logging — the Node no longer produces excessive log output when there is no MCP traffic\n* Fixed the [CVE-2026-39821](https://nvd.nist.gov/vuln/detail/CVE-2026-39821) vulnerability in [API Specification Enforcement](../api-specification-enforcement/overview.md)\n\n#### Amazon Machine Image (AMI)\n\n* Improved [MCP (Model Context Protocol)](../api-discovery/exploring.md#mcp-servers) traffic analysis logging — the Node no longer produces excessive log output when there is no MCP traffic\n* Fixed the [CVE-2026-39821](https://nvd.nist.gov/vuln/detail/CVE-2026-39821) vulnerability in [API Specification Enforcement](../api-specification-enforcement/overview.md)"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.12.5",
    "line": "6.x",
    "date": "2026-06-12",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6125-2026-06-12",
    "body_markdown": "#### All-in-one installer\n\n* Added support for the latest Alpine and Debian/Ubuntu distribution NGINX package rebuilds shipping the upstream fix for [CVE-2026-49975](https://nvd.nist.gov/vuln/detail/CVE-2026-49975)\n* Added support for NGINX Plus R37\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Internal improvements\n\n#### Helm chart for Sidecar\n\n* Fixed the [CVE-2026-49975](https://nvd.nist.gov/vuln/detail/CVE-2026-49975) NGINX vulnerability\n\n#### NGINX-based Docker image\n\n* Fixed the [CVE-2026-49975](https://nvd.nist.gov/vuln/detail/CVE-2026-49975) NGINX vulnerability\n\n#### Amazon Machine Image (AMI)\n\n* Fixed the [CVE-2026-49975](https://nvd.nist.gov/vuln/detail/CVE-2026-49975) NGINX vulnerability"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.12.4",
    "line": "6.x",
    "date": "2026-06-04",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6124-2026-06-04",
    "body_markdown": "#### All-in-one installer\n\n* Added support for NGINX stable 1.30.2\n* Added support for NGINX mainline 1.31.1\n* Added support for OpenResty 1.31.1.1\n* Changed the [Limit data export](../admin-en/export-to-cloud.md) rule — when applied, the node now preserves the request structure (parameter names and nesting) and masks only the values, instead of switching the matched traffic to metadata only\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Changed the [Limit data export](../admin-en/export-to-cloud.md) rule — when applied, the node now preserves the request structure (parameter names and nesting) and masks only the values, instead of switching the matched traffic to metadata only\n\n#### Helm chart for Sidecar\n\n* Changed the [Limit data export](../admin-en/export-to-cloud.md) rule — when applied, the node now preserves the request structure (parameter names and nesting) and masks only the values, instead of switching the matched traffic to metadata only\n\n#### NGINX-based Docker image\n\n* Changed the [Limit data export](../admin-en/export-to-cloud.md) rule — when applied, the node now preserves the request structure (parameter names and nesting) and masks only the values, instead of switching the matched traffic to metadata only\n\n#### Amazon Machine Image (AMI)\n\n* Changed the [Limit data export](../admin-en/export-to-cloud.md) rule — when applied, the node now preserves the request structure (parameter names and nesting) and masks only the values, instead of switching the matched traffic to metadata only"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.12.3",
    "line": "6.x",
    "date": "2026-05-25",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6123-2026-05-25",
    "body_markdown": "#### All-in-one installer\n\n* Added BoringSSL compatibility — the Wallarm NGINX module can now run on BoringSSL-linked NGINX builds. [JA4 TLS fingerprinting](../admin-en/configure-parameters-en.md#wallarm_fingerprint) and encrypted upstream traffic to the postanalytics service are disabled when the build lacks the required symbols\n* Fixed the HEX parser producing false detections on very short alphanumeric inputs such as two-character values\n* Fixed HEX-encoded points in serialized requests causing parsing errors in the postanalytics service and [API Discovery](../api-discovery/overview.md)\n* Fixed [API Discovery](../api-discovery/overview.md) inferring the wrong content type for responses — the value is now read from request-level metadata instead of the response `Content-Type` header\n* Fixed gRPC and WebSocket responses being blocked on detected infoleaks\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added BoringSSL compatibility — the Wallarm NGINX module can now run on BoringSSL-linked NGINX builds. [JA4 TLS fingerprinting](../admin-en/configure-parameters-en.md#wallarm_fingerprint) and encrypted upstream traffic to the postanalytics service are disabled when the build lacks the required symbols\n* Fixed the HEX parser producing false detections on very short alphanumeric inputs such as two-character values\n* Fixed HEX-encoded points in serialized requests causing parsing errors in the postanalytics service and [API Discovery](../api-discovery/overview.md)\n* Fixed [API Discovery](../api-discovery/overview.md) inferring the wrong content type for responses — the value is now read from request-level metadata instead of the response `Content-Type` header\n* Fixed gRPC and WebSocket responses being blocked on detected infoleaks\n\n#### Helm chart for Sidecar\n\n* Added BoringSSL compatibility — the Wallarm NGINX module can now run on BoringSSL-linked NGINX builds. [JA4 TLS fingerprinting](../admin-en/configure-parameters-en.md#wallarm_fingerprint) and encrypted upstream traffic to the postanalytics service are disabled when the build lacks the required symbols\n* Fixed the HEX parser producing false detections on very short alphanumeric inputs such as two-character values\n* Fixed HEX-encoded points in serialized requests causing parsing errors in the postanalytics service and [API Discovery](../api-discovery/overview.md)\n* Fixed [API Discovery](../api-discovery/overview.md) inferring the wrong content type for responses — the value is now read from request-level metadata instead of the response `Content-Type` header\n* Fixed gRPC and WebSocket responses being blocked on detected infoleaks\n\n#### NGINX-based Docker image\n\n* Added BoringSSL compatibility — the Wallarm NGINX module can now run on BoringSSL-linked NGINX builds. [JA4 TLS fingerprinting](../admin-en/configure-parameters-en.md#wallarm_fingerprint) and encrypted upstream traffic to the postanalytics service are disabled when the build lacks the required symbols\n* Fixed the HEX parser producing false detections on very short alphanumeric inputs such as two-character values\n* Fixed HEX-encoded points in serialized requests causing parsing errors in the postanalytics service and [API Discovery](../api-discovery/overview.md)\n* Fixed [API Discovery](../api-discovery/overview.md) inferring the wrong content type for responses — the value is now read from request-level metadata instead of the response `Content-Type` header\n* Fixed gRPC and WebSocket responses being blocked on detected infoleaks\n\n#### Amazon Machine Image (AMI)\n\n* Added BoringSSL compatibility — the Wallarm NGINX module can now run on BoringSSL-linked NGINX builds. [JA4 TLS fingerprinting](../admin-en/configure-parameters-en.md#wallarm_fingerprint) and encrypted upstream traffic to the postanalytics service are disabled when the build lacks the required symbols\n* Fixed the HEX parser producing false detections on very short alphanumeric inputs such as two-character values\n* Fixed HEX-encoded points in serialized requests causing parsing errors in the postanalytics service and [API Discovery](../api-discovery/overview.md)\n* Fixed [API Discovery](../api-discovery/overview.md) inferring the wrong content type for responses — the value is now read from request-level metadata instead of the response `Content-Type` header\n* Fixed gRPC and WebSocket responses being blocked on detected infoleaks"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.12.2",
    "line": "6.x",
    "date": "2026-05-19",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6122-2026-05-19",
    "body_markdown": "#### All-in-one installer\n\n* Added support for NGINX stable 1.30.1\n* Added support for NGINX mainline 1.31.0\n\nTo mitigate the risk of the NGINX vulnerabilities [CVE-2026-42945](https://nvd.nist.gov/vuln/detail/CVE-2026-42945), [CVE-2026-42946](https://nvd.nist.gov/vuln/detail/CVE-2026-42946), [CVE-2026-40460](https://nvd.nist.gov/vuln/detail/CVE-2026-40460), [CVE-2026-42934](https://nvd.nist.gov/vuln/detail/CVE-2026-42934), and [CVE-2026-40701](https://nvd.nist.gov/vuln/detail/CVE-2026-40701), upgrade NGINX to stable 1.30.1 or mainline 1.31.0 and update Wallarm Node to 6.12.2.\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Pulled in a curl/libcurl security patch from the Alpine base image: [CVE-2026-3805](https://nvd.nist.gov/vuln/detail/CVE-2026-3805).\n\n#### Helm chart for Sidecar\n\n* Pulled in NGINX security patches from the base image: [CVE-2026-42945](https://nvd.nist.gov/vuln/detail/CVE-2026-42945), [CVE-2026-42946](https://nvd.nist.gov/vuln/detail/CVE-2026-42946), [CVE-2026-40460](https://nvd.nist.gov/vuln/detail/CVE-2026-40460), [CVE-2026-42934](https://nvd.nist.gov/vuln/detail/CVE-2026-42934), and [CVE-2026-40701](https://nvd.nist.gov/vuln/detail/CVE-2026-40701).\n\n#### NGINX-based Docker image\n\n* Pulled in NGINX security patches from the Alpine base image: [CVE-2026-42945](https://nvd.nist.gov/vuln/detail/CVE-2026-42945), [CVE-2026-42946](https://nvd.nist.gov/vuln/detail/CVE-2026-42946), [CVE-2026-40460](https://nvd.nist.gov/vuln/detail/CVE-2026-40460), [CVE-2026-42934](https://nvd.nist.gov/vuln/detail/CVE-2026-42934), and [CVE-2026-40701](https://nvd.nist.gov/vuln/detail/CVE-2026-40701).\n\n#### Amazon Machine Image (AMI)\n\n* Pulled in NGINX security patches from the Debian base image: [CVE-2026-27651](https://nvd.nist.gov/vuln/detail/CVE-2026-27651), [CVE-2026-27654](https://nvd.nist.gov/vuln/detail/CVE-2026-27654), [CVE-2026-27784](https://nvd.nist.gov/vuln/detail/CVE-2026-27784), [CVE-2026-28753](https://nvd.nist.gov/vuln/detail/CVE-2026-28753), [CVE-2026-28755](https://nvd.nist.gov/vuln/detail/CVE-2026-28755), [CVE-2026-32647](https://nvd.nist.gov/vuln/detail/CVE-2026-32647), [CVE-2026-40701](https://nvd.nist.gov/vuln/detail/CVE-2026-40701), [CVE-2026-42934](https://nvd.nist.gov/vuln/detail/CVE-2026-42934), [CVE-2026-42945](https://nvd.nist.gov/vuln/detail/CVE-2026-42945), and [CVE-2026-42946](https://nvd.nist.gov/vuln/detail/CVE-2026-42946)."
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.12.1",
    "line": "6.x",
    "date": "2026-05-12",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6121-2026-05-12",
    "body_markdown": "#### All-in-one installer\n\n* Internal improvements\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added optional human-readable label support to the [`nginx.ingress.kubernetes.io/wallarm-partner-client-uuid`](../admin-en/configure-kubernetes-en.md#ingress-annotations) annotation, aligning it with the [`wallarm_partner_client_uuid`](../admin-en/configure-parameters-en.md#wallarm_partner_client_uuid) directive (added in NGINX Node 6.12.0)\n\n    Pass the UUID and label as a space-separated value: `\"<UUID> <LABEL>\"`.\n\n#### Helm chart for Sidecar\n\n* Internal improvements\n\n#### NGINX-based Docker image\n\n* Internal improvements\n\n#### Amazon Machine Image (AMI)\n\n* Internal improvements"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.12.0",
    "line": "6.x",
    "date": "2026-05-04",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6120-2026-05-04",
    "body_markdown": "#### All-in-one installer\n\n* Added support for [MCP server discovery](../api-discovery/exploring.md#mcp-servers) in API Discovery\n* Added support for [MCP Sessions](../api-sessions/mcp-sessions.md)\n* Added [MCP mitigation controls](../agentic-ai/mcp-mitigation-controls.md): ACL policy, request verification, and tool input schema enforcement\n* Added the [`wallarm_enable_mcp`](../admin-en/configure-parameters-en.md#wallarm_enable_mcp) directive to enable or disable MCP traffic inspection (enabled by default)\n\n    Set it to `off` to stop MCP processing on deployments that do not use MCP discovery and protection.\n* Added HEX encoding attack detection — the Node now decodes and analyzes HEX-encoded payloads, improving protection against obfuscation-based bypass techniques\n* Added per-tenant statistics and logging in [multi-tenant](../installation/multi-tenant/overview.md) deployments:\n\n    * The [`wallarm_partner_client_uuid`](../admin-en/configure-parameters-en.md#wallarm_partner_client_uuid) directive now accepts an optional human-readable label\n    * Two new NGINX variables (`$wallarm_partner_client_uuid`, `$wallarm_partner_client_label`) are available for use in [extended log formats](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n    * The [`wallarm_status`](../admin-en/configure-statistics-service.md) endpoint now includes per-tenant traffic breakdown in both JSON and Prometheus output formats — per-application (`wallarm_*_per_app_total` metrics) and per-group (`wallarm_*_per_group_total` metrics) via the [`wallarm_status_group`](../admin-en/configure-parameters-en.md#wallarm_status_group) directive\n* Added `?format=json` and `?format=prometheus` query parameter support to the [`wallarm_status`](../admin-en/configure-statistics-service.md) endpoint, allowing the output format to be overridden at request time\n* Fixed [API Specification Enforcement](../api-specification-enforcement/overview.md) incorrectly reporting requests as \"undefined endpoint\" for OpenAPI specs that define a base path in the `servers` block\n* Bumped Go version to 1.26.1\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added support for [MCP server discovery](../api-discovery/exploring.md#mcp-servers) in API Discovery\n* Added support for [MCP Sessions](../api-sessions/mcp-sessions.md)\n* Added [MCP mitigation controls](../agentic-ai/mcp-mitigation-controls.md): ACL policy, request verification, and tool input schema enforcement\n* Added the [`wallarm_enable_mcp`](../admin-en/configure-parameters-en.md#wallarm_enable_mcp) directive to enable or disable MCP traffic inspection (enabled by default)\n\n    Set it to `off` to stop MCP processing on deployments that do not use MCP discovery and protection.\n* Added HEX encoding attack detection — the Node now decodes and analyzes HEX-encoded payloads, improving protection against obfuscation-based bypass techniques\n* Added per-tenant statistics and logging in [multi-tenant](../installation/multi-tenant/overview.md) deployments:\n\n    * The [`wallarm_partner_client_uuid`](../admin-en/configure-parameters-en.md#wallarm_partner_client_uuid) directive now accepts an optional human-readable label\n    * Two new NGINX variables (`$wallarm_partner_client_uuid`, `$wallarm_partner_client_label`) are available for use in [extended log formats](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n    * The [`wallarm_status`](../admin-en/configure-statistics-service.md) endpoint now includes per-tenant traffic breakdown in both JSON and Prometheus output formats — per-application (`wallarm_*_per_app_total` metrics) and per-group (`wallarm_*_per_group_total` metrics) via the [`wallarm_status_group`](../admin-en/configure-parameters-en.md#wallarm_status_group) directive\n* Added `?format=json` and `?format=prometheus` query parameter support to the [`wallarm_status`](../admin-en/configure-statistics-service.md) endpoint, allowing the output format to be overridden at request time\n* Fixed [API Specification Enforcement](../api-specification-enforcement/overview.md) incorrectly reporting requests as \"undefined endpoint\" for OpenAPI specs that define a base path in the `servers` block\n* Bumped Go version to 1.26.1\n* Fixed security vulnerabilities:\n\n    * [CVE-2026-33810](https://www.cve.org/CVERecord?id=CVE-2026-33810)\n    * [CVE-2026-32283](https://www.cve.org/CVERecord?id=CVE-2026-32283)\n    * [CVE-2026-32281](https://www.cve.org/CVERecord?id=CVE-2026-32281)\n    * [CVE-2026-32280](https://www.cve.org/CVERecord?id=CVE-2026-32280)\n    * [CVE-2026-32282](https://www.cve.org/CVERecord?id=CVE-2026-32282)\n    * [CVE-2026-32289](https://www.cve.org/CVERecord?id=CVE-2026-32289)\n    * [CVE-2026-32288](https://www.cve.org/CVERecord?id=CVE-2026-32288)\n\n#### Helm chart for Sidecar\n\n* Added support for [MCP server discovery](../api-discovery/exploring.md#mcp-servers) in API Discovery\n* Added support for [MCP Sessions](../api-sessions/mcp-sessions.md)\n* Added [MCP mitigation controls](../agentic-ai/mcp-mitigation-controls.md): ACL policy, request verification, and tool input schema enforcement\n* Added the [`wallarm_enable_mcp`](../admin-en/configure-parameters-en.md#wallarm_enable_mcp) directive to enable or disable MCP traffic inspection (enabled by default)\n\n    Set it to `off` to stop MCP processing on deployments that do not use MCP discovery and protection.\n* Added HEX encoding attack detection — the Node now decodes and analyzes HEX-encoded payloads, improving protection against obfuscation-based bypass techniques\n* Added per-tenant statistics and logging in [multi-tenant](../installation/multi-tenant/overview.md) deployments:\n\n    * The [`wallarm_partner_client_uuid`](../admin-en/configure-parameters-en.md#wallarm_partner_client_uuid) directive now accepts an optional human-readable label\n    * Two new NGINX variables (`$wallarm_partner_client_uuid`, `$wallarm_partner_client_label`) are available for use in [extended log formats](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n    * The [`wallarm_status`](../admin-en/configure-statistics-service.md) endpoint now includes per-tenant traffic breakdown in both JSON and Prometheus output formats — per-application (`wallarm_*_per_app_total` metrics) and per-group (`wallarm_*_per_group_total` metrics) via the [`wallarm_status_group`](../admin-en/configure-parameters-en.md#wallarm_status_group) directive\n* Added `?format=json` and `?format=prometheus` query parameter support to the [`wallarm_status`](../admin-en/configure-statistics-service.md) endpoint, allowing the output format to be overridden at request time\n* Fixed [API Specification Enforcement](../api-specification-enforcement/overview.md) incorrectly reporting requests as \"undefined endpoint\" for OpenAPI specs that define a base path in the `servers` block\n* Bumped Go version to 1.26.1\n* Fixed the [CVE-2026-34743](https://www.cve.org/CVERecord?id=CVE-2026-34743) security vulnerability\n\n#### NGINX-based Docker image\n\n* Added support for [MCP server discovery](../api-discovery/exploring.md#mcp-servers) in API Discovery\n* Added support for [MCP Sessions](../api-sessions/mcp-sessions.md)\n* Added [MCP mitigation controls](../agentic-ai/mcp-mitigation-controls.md): ACL policy, request verification, and tool input schema enforcement\n* Added the [`wallarm_enable_mcp`](../admin-en/configure-parameters-en.md#wallarm_enable_mcp) directive to enable or disable MCP traffic inspection (enabled by default)\n\n    Set it to `off` to stop MCP processing on deployments that do not use MCP discovery and protection.\n* Added HEX encoding attack detection — the Node now decodes and analyzes HEX-encoded payloads, improving protection against obfuscation-based bypass techniques\n* Added per-tenant statistics and logging in [multi-tenant](../installation/multi-tenant/overview.md) deployments:\n\n    * The [`wallarm_partner_client_uuid`](../admin-en/configure-parameters-en.md#wallarm_partner_client_uuid) directive now accepts an optional human-readable label\n    * Two new NGINX variables (`$wallarm_partner_client_uuid`, `$wallarm_partner_client_label`) are available for use in [extended log formats](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n    * The [`wallarm_status`](../admin-en/configure-statistics-service.md) endpoint now includes per-tenant traffic breakdown in both JSON and Prometheus output formats — per-application (`wallarm_*_per_app_total` metrics) and per-group (`wallarm_*_per_group_total` metrics) via the [`wallarm_status_group`](../admin-en/configure-parameters-en.md#wallarm_status_group) directive\n* Added `?format=json` and `?format=prometheus` query parameter support to the [`wallarm_status`](../admin-en/configure-statistics-service.md) endpoint, allowing the output format to be overridden at request time\n* Fixed [API Specification Enforcement](../api-specification-enforcement/overview.md) incorrectly reporting requests as \"undefined endpoint\" for OpenAPI specs that define a base path in the `servers` block\n* Bumped Go version to 1.26.1\n\n#### Amazon Machine Image (AMI)\n\n* Added support for [MCP server discovery](../api-discovery/exploring.md#mcp-servers) in API Discovery\n* Added support for [MCP Sessions](../api-sessions/mcp-sessions.md)\n* Added [MCP mitigation controls](../agentic-ai/mcp-mitigation-controls.md): ACL policy, request verification, and tool input schema enforcement\n* Added the [`wallarm_enable_mcp`](../admin-en/configure-parameters-en.md#wallarm_enable_mcp) directive to enable or disable MCP traffic inspection (enabled by default)\n\n    Set it to `off` to stop MCP processing on deployments that do not use MCP discovery and protection.\n* Added HEX encoding attack detection — the Node now decodes and analyzes HEX-encoded payloads, improving protection against obfuscation-based bypass techniques\n* Added per-tenant statistics and logging in [multi-tenant](../installation/multi-tenant/overview.md) deployments:\n\n    * The [`wallarm_partner_client_uuid`](../admin-en/configure-parameters-en.md#wallarm_partner_client_uuid) directive now accepts an optional human-readable label\n    * Two new NGINX variables (`$wallarm_partner_client_uuid`, `$wallarm_partner_client_label`) are available for use in [extended log formats](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n    * The [`wallarm_status`](../admin-en/configure-statistics-service.md) endpoint now includes per-tenant traffic breakdown in both JSON and Prometheus output formats — per-application (`wallarm_*_per_app_total` metrics) and per-group (`wallarm_*_per_group_total` metrics) via the [`wallarm_status_group`](../admin-en/configure-parameters-en.md#wallarm_status_group) directive\n* Added `?format=json` and `?format=prometheus` query parameter support to the [`wallarm_status`](../admin-en/configure-statistics-service.md) endpoint, allowing the output format to be overridden at request time\n* Fixed [API Specification Enforcement](../api-specification-enforcement/overview.md) incorrectly reporting requests as \"undefined endpoint\" for OpenAPI specs that define a base path in the `servers` block\n* Bumped Go version to 1.26.1"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.11.3",
    "line": "6.x",
    "date": "2026-04-29",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6113-2026-04-29",
    "body_markdown": "#### All-in-one installer\n\n* Added support for NGINX mainline 1.29.8\n* Added support for NGINX stable 1.30.0\n* Fixed intermittent errors in custom ruleset loading and GraphQL processing\n* Fixed NGINX worker crash (signal 11) when serving [custom blocking pages](../admin-en/configuration-guides/configure-block-page-and-code.md) configured via file path while response header modification rules were active\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed intermittent errors in custom ruleset loading and GraphQL processing\n* Fixed NGINX worker crash (signal 11) when serving [custom blocking pages](../admin-en/configuration-guides/configure-block-page-and-code.md) configured via file path while response header modification rules were active\n\n#### Helm chart for Sidecar\n\n* Fixed intermittent errors in custom ruleset loading and GraphQL processing\n* Fixed NGINX worker crash (signal 11) when serving [custom blocking pages](../admin-en/configuration-guides/configure-block-page-and-code.md) configured via file path while response header modification rules were active\n\n#### NGINX-based Docker image\n\n* Fixed intermittent errors in custom ruleset loading and GraphQL processing\n* Fixed NGINX worker crash (signal 11) when serving [custom blocking pages](../admin-en/configuration-guides/configure-block-page-and-code.md) configured via file path while response header modification rules were active"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.11.2",
    "line": "6.x",
    "date": "2026-03-27",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6112-2026-03-27",
    "body_markdown": "#### All-in-one installer\n\n* Added compatibility with latest NGINX versions shipped by RHEL-based distros\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Internal improvements\n\n#### Helm chart for Sidecar\n\n* Bump Alpine version to 3.23\n* Upgrade NGINX to version 1.28.3\n\n#### NGINX-based Docker image\n\n* Bump Alpine version to 3.23\n* Upgrade NGINX to version 1.28.3\n\n#### Amazon Machine Image (AMI)\n\n* Internal improvements"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.11.1",
    "line": "6.x",
    "date": "2026-03-25",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6111-2026-03-25",
    "body_markdown": "#### All-in-one installer\n\n* Added support for NGINX stable 1.28.3\n* Added support for NGINX mainline 1.29.7\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added [authentication flow detection](../api-discovery/authentication.md) in API Discovery — automatically identifies authentication methods used by each endpoint and highlights unauthenticated endpoints\n* Upgraded to Community Ingress NGINX Controller version [1.15.0](https://github.com/kubernetes/ingress-nginx/releases/tag/controller-v1.15.0), aligning with the upstream Helm chart version 4.15.0\n\n    The underlying NGINX has been updated to 1.27.1 and the base Alpine image to 3.23.3.\n\n    Supported Kubernetes versions are now 1.31–1.35.\n* Fixed empty response (`000` status code) instead of [custom block page](../admin-en/configuration-guides/configure-block-page-and-code.md) when [`ngx_http_auth_request_module`](https://nginx.org/en/docs/http/ngx_http_auth_request_module.html) is used\n* Fixed the [GHSA-6g7g-w4f8-9c9x](https://github.com/advisories/GHSA-6g7g-w4f8-9c9x) vulnerability\n* Bumped Go version to 1.26.1\n\n#### Helm chart for Sidecar\n\n* Added [authentication flow detection](../api-discovery/authentication.md) in API Discovery — automatically identifies authentication methods used by each endpoint and highlights unauthenticated endpoints\n* Fixed empty response (`000` status code) instead of [custom block page](../admin-en/configuration-guides/configure-block-page-and-code.md) when [`ngx_http_auth_request_module`](https://nginx.org/en/docs/http/ngx_http_auth_request_module.html) is used\n* Fixed the [GHSA-6g7g-w4f8-9c9x](https://github.com/advisories/GHSA-6g7g-w4f8-9c9x) vulnerability\n* Bumped Go version to 1.26.1\n\n#### NGINX-based Docker image\n\n* Added [authentication flow detection](../api-discovery/authentication.md) in API Discovery — automatically identifies authentication methods used by each endpoint and highlights unauthenticated endpoints\n* Fixed empty response (`000` status code) instead of [custom block page](../admin-en/configuration-guides/configure-block-page-and-code.md) when [`ngx_http_auth_request_module`](https://nginx.org/en/docs/http/ngx_http_auth_request_module.html) is used\n* Fixed the [GHSA-6g7g-w4f8-9c9x](https://github.com/advisories/GHSA-6g7g-w4f8-9c9x) vulnerability\n* Bumped Go version to 1.26.1\n\n#### Amazon Machine Image (AMI)\n\n* Added [authentication flow detection](../api-discovery/authentication.md) in API Discovery — automatically identifies authentication methods used by each endpoint and highlights unauthenticated endpoints\n* Fixed empty response (`000` status code) instead of [custom block page](../admin-en/configuration-guides/configure-block-page-and-code.md) when [`ngx_http_auth_request_module`](https://nginx.org/en/docs/http/ngx_http_auth_request_module.html) is used\n* Fixed the [GHSA-6g7g-w4f8-9c9x](https://github.com/advisories/GHSA-6g7g-w4f8-9c9x) vulnerability\n* Bumped Go version to 1.26.1"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.11.0",
    "line": "6.x",
    "date": "2026-03-25",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6110-2026-03-25",
    "body_markdown": "#### All-in-one installer\n\n* Added [authentication flow detection](../api-discovery/authentication.md) in API Discovery — automatically identifies authentication methods used by each endpoint and highlights unauthenticated endpoints\n* Fixed empty response (`000` status code) instead of [custom block page](../admin-en/configuration-guides/configure-block-page-and-code.md) when [`ngx_http_auth_request_module`](https://nginx.org/en/docs/http/ngx_http_auth_request_module.html) is used\n* Fixed the [GHSA-6g7g-w4f8-9c9x](https://github.com/advisories/GHSA-6g7g-w4f8-9c9x) vulnerability\n* Bumped Go version to 1.26.1"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.10.3",
    "line": "6.x",
    "date": "2026-03-16",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6103-2026-03-16",
    "body_markdown": "#### All-in-one installer\n\n* Fixed a memory leak in the [API Specification Enforcement](../api-specification-enforcement/overview.md) component that caused steadily increasing memory consumption and eventual OOMKill pod restarts\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed a memory leak in the [API Specification Enforcement](../api-specification-enforcement/overview.md) component that caused steadily increasing memory consumption and eventual OOMKill pod restarts\n\n#### Helm chart for Sidecar\n\n* Fixed a memory leak in the [API Specification Enforcement](../api-specification-enforcement/overview.md) component that caused steadily increasing memory consumption and eventual OOMKill pod restarts\n\n#### NGINX-based Docker image\n\n* Fixed a memory leak in the [API Specification Enforcement](../api-specification-enforcement/overview.md) component that caused steadily increasing memory consumption and eventual OOMKill pod restarts\n\n#### Amazon Machine Image (AMI)\n\n* Fixed a memory leak in the [API Specification Enforcement](../api-specification-enforcement/overview.md) component that caused steadily increasing memory consumption and eventual OOMKill pod restarts"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.10.2",
    "line": "6.x",
    "date": "2026-03-10",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6102-2026-03-10",
    "body_markdown": "#### All-in-one installer\n\n* Added new traffic metrics to the [`wallarm-status`](../admin-en/configure-statistics-service.md) statistics service: `bytes_blocked_in`, `bytes_blocked_out`, `bytes_blocked_by_acl_in`, and `bytes_blocked_by_acl_out`\n\n    These counters track the volume of incoming and outgoing traffic in blocked requests, split by block reason (attack/overlimit/antibot vs. denylists). Available in JSON, Prometheus, and per-application split formats.\n* Fixed a shared memory allocation bug in the statistics service initialization that could lead to data corruption under high load\n* Fixed memory limit handling for **wcli** jobs\n* Fixed security vulnerabilities:\n\n    * [CVE-2025-68121](https://www.cve.org/CVERecord?id=CVE-2025-68121)\n    * [CVE-2026-25646](https://www.cve.org/CVERecord?id=CVE-2026-25646)\n    * [CVE-2025-61726](https://www.cve.org/CVERecord?id=CVE-2025-61726)\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added new traffic metrics to the [`wallarm-status`](../admin-en/configure-statistics-service.md) statistics service: `bytes_blocked_in`, `bytes_blocked_out`, `bytes_blocked_by_acl_in`, and `bytes_blocked_by_acl_out`\n\n    These counters track the volume of incoming and outgoing traffic in blocked requests, split by block reason (attack/overlimit/antibot vs. denylists). Available in JSON, Prometheus, and per-application split formats.\n* Fixed a shared memory allocation bug in the statistics service initialization that could lead to data corruption under high load\n* Fixed memory limit handling for **wcli** jobs\n* Fixed security vulnerabilities:\n\n    * [CVE-2025-68121](https://www.cve.org/CVERecord?id=CVE-2025-68121)\n    * [CVE-2026-25646](https://www.cve.org/CVERecord?id=CVE-2026-25646)\n    * [CVE-2025-61726](https://www.cve.org/CVERecord?id=CVE-2025-61726)\n\n#### Helm chart for Sidecar\n\n* Added new traffic metrics to the [`wallarm-status`](../admin-en/configure-statistics-service.md) statistics service: `bytes_blocked_in`, `bytes_blocked_out`, `bytes_blocked_by_acl_in`, and `bytes_blocked_by_acl_out`\n\n    These counters track the volume of incoming and outgoing traffic in blocked requests, split by block reason (attack/overlimit/antibot vs. denylists). Available in JSON, Prometheus, and per-application split formats.\n* Fixed a shared memory allocation bug in the statistics service initialization that could lead to data corruption under high load\n* Fixed memory limit handling for **wcli** jobs\n* Fixed security vulnerabilities:\n\n    * [CVE-2025-68121](https://www.cve.org/CVERecord?id=CVE-2025-68121)\n    * [CVE-2026-25646](https://www.cve.org/CVERecord?id=CVE-2026-25646)\n    * [CVE-2025-61726](https://www.cve.org/CVERecord?id=CVE-2025-61726)\n\n#### NGINX-based Docker image\n\n* Added new traffic metrics to the [`wallarm-status`](../admin-en/configure-statistics-service.md) statistics service: `bytes_blocked_in`, `bytes_blocked_out`, `bytes_blocked_by_acl_in`, and `bytes_blocked_by_acl_out`\n\n    These counters track the volume of incoming and outgoing traffic in blocked requests, split by block reason (attack/overlimit/antibot vs. denylists). Available in JSON, Prometheus, and per-application split formats.\n* Fixed a shared memory allocation bug in the statistics service initialization that could lead to data corruption under high load\n* Fixed memory limit handling for **wcli** jobs\n* Fixed security vulnerabilities:\n\n    * CVE-2025-68121\n    * CVE-2026-25646\n    * CVE-2025-61726\n\n#### Amazon Machine Image (AMI)\n\n* Added new traffic metrics to the [`wallarm-status`](../admin-en/configure-statistics-service.md) statistics service: `bytes_blocked_in`, `bytes_blocked_out`, `bytes_blocked_by_acl_in`, and `bytes_blocked_by_acl_out`\n\n    These counters track the volume of incoming and outgoing traffic in blocked requests, split by block reason (attack/overlimit/antibot vs. denylists). Available in JSON, Prometheus, and per-application split formats.\n* Fixed a shared memory allocation bug in the statistics service initialization that could lead to data corruption under high load\n* Fixed memory limit handling for **wcli** jobs\n* Fixed security vulnerabilities:\n\n    * [CVE-2025-68121](https://www.cve.org/CVERecord?id=CVE-2025-68121)\n    * [CVE-2026-25646](https://www.cve.org/CVERecord?id=CVE-2026-25646)\n    * [CVE-2025-61726](https://www.cve.org/CVERecord?id=CVE-2025-61726)"
  },
  {
    "artifact_id": "nginx-node",
    "version": "0.23.0",
    "line": "6.x",
    "date": "2026-02-28",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#0230-2026-02-28",
    "body_markdown": "#### Helm chart for eBPF-based solution\n\n* Updated the eBPF-based solution (beta) for [API Discovery](../api-discovery/overview.md) — building your API inventory based on real traffic without impacting production\n* Switched the processing component from NGINX-based node (`wallarm/node-nginx`) to [Native Node](../installation/nginx-native-node-internals.md#native-node) (`wallarm/node-native-processing`), added `config.connector` section for its [configuration](../installation/oob/ebpf/helm-chart-for-wallarm.md#configconnector)\n* Enabled metrics by default for processing and agent components\n* Renamed and restructured Helm chart parameters:\n\n    | What changed | Old value | New value |\n    | --- | --- | --- |\n    | Aggregation in-memory storage parameter | `config.aggregation.tarantoolMemory` | `config.aggregation.wstoreMemory` |\n    | Process manager configuration section | `config.supervisord` | `config.wcli` |\n    | Responder section | `config.responder` | Removed |\n    | Processing pod containers | `node`, `responder`, `supervisord`, `collectd` | `nodeNative`, `wcli` |\n    | Aggregation pod containers | `supervisord`, `tarantool`, `appStructure`, `antiBot` | `wcli`, `wstore` |"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.10.1",
    "line": "6.x",
    "date": "2026-02-18",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6101-2026-02-18",
    "body_markdown": "#### All-in-one installer\n\n* Added support for circular references in OpenAPI specifications uploaded for [API Specification Enforcement](../api-specification-enforcement/overview.md)\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added support for circular references in OpenAPI specifications uploaded for [API Specification Enforcement](../api-specification-enforcement/overview.md)\n\n#### Helm chart for Sidecar\n\n* Added support for circular references in OpenAPI specifications uploaded for [API Specification Enforcement](../api-specification-enforcement/overview.md)\n\n#### NGINX-based Docker image\n\n* Added support for circular references in OpenAPI specifications uploaded for [API Specification Enforcement](../api-specification-enforcement/overview.md)\n\n#### Amazon Machine Image (AMI)\n\n* Added support for circular references in OpenAPI specifications uploaded for [API Specification Enforcement](../api-specification-enforcement/overview.md)"
  },
  {
    "artifact_id": "nginx-node",
    "version": "7.0.0",
    "line": "7.x",
    "date": "2026-02-16",
    "url": "https://docs.wallarm.com/7.x/updating-migrating/node-artifact-versions/#700-2026-02-16",
    "body_markdown": "#### Helm chart for Wallarm NGINX Ingress controller\n\n* Initial release 7.0, [see changelog](what-is-new.md)"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.10.0",
    "line": "6.x",
    "date": "2026-02-09",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#6100-2026-02-09",
    "body_markdown": "#### All-in-one installer\n\n* Added support for OpenAPI v3 specifications with non-string (for example, integer) YAML keys in [API Specification Enforcement](../api-specification-enforcement/overview.md). This improves compatibility and prevents schema parsing failures\n* Added support for NGINX stable 1.28.2\n* Fixed an issue where the Node sent too many requests in a single batch to **wstore**, causing submission failures\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added support for OpenAPI v3 specifications with non-string (for example, integer) YAML keys in [API Specification Enforcement](../api-specification-enforcement/overview.md). This improves compatibility and prevents schema parsing failures\n* Fixed an issue where the Node sent too many requests in a single batch to **wstore**, causing submission failures\n\n#### Helm chart for Sidecar\n\n* Added support for OpenAPI v3 specifications with non-string (for example, integer) YAML keys in [API Specification Enforcement](../api-specification-enforcement/overview.md). This improves compatibility and prevents schema parsing failures\n* Fixed an issue where the Node sent too many requests in a single batch to **wstore**, causing submission failures\n\n#### NGINX-based Docker image\n\n* Added support for OpenAPI v3 specifications with non-string (for example, integer) YAML keys in [API Specification Enforcement](../api-specification-enforcement/overview.md). This improves compatibility and prevents schema parsing failures\n* Fixed an issue where the Node sent too many requests in a single batch to **wstore**, causing submission failures\n\n#### Amazon Machine Image (AMI)\n\n* Added support for OpenAPI v3 specifications with non-string (for example, integer) YAML keys in [API Specification Enforcement](../api-specification-enforcement/overview.md). This improves compatibility and prevents schema parsing failures\n* Fixed an issue where the Node sent too many requests in a single batch to **wstore**, causing submission failures"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.19",
    "line": "5.x",
    "date": "2026-01-23",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#5319-2026-01-23",
    "body_markdown": "#### All-in-one installer\n\n* Added support for NGINX stable 1.28.1"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.9.0",
    "line": "6.x",
    "date": "2026-01-15",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#690-2026-01-15",
    "body_markdown": "#### All-in-one installer\n\n* Increased the frequency of session updates sent to the Wallarm Cloud. Sessions now appear in the UI faster, closer to real time\n* Improved memory usage monitoring and prevention of resource exhaustion\n* Added support for NGINX stable 1.28.1\n* Fixed the [CVE-2026-21441](https://scout.docker.com/vulnerabilities/id/CVE-2026-21441) vulnerability\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Increased the frequency of session updates sent to the Wallarm Cloud. Sessions now appear in the UI faster, closer to real time\n* Improved memory usage monitoring and prevention of resource exhaustion\n* Fixed the [CVE-2026-21441](https://scout.docker.com/vulnerabilities/id/CVE-2026-21441) vulnerability\n\n#### Helm chart for Sidecar\n\n* Increased the frequency of session updates sent to the Wallarm Cloud. Sessions now appear in the UI faster, closer to real time\n* Improved memory usage monitoring and prevention of resource exhaustion\n* Fixed the [CVE-2026-21441](https://scout.docker.com/vulnerabilities/id/CVE-2026-21441) vulnerability\n\n#### NGINX-based Docker image\n\n* Increased the frequency of session updates sent to the Wallarm Cloud. Sessions now appear in the UI faster, closer to real time\n* Improved memory usage monitoring and prevention of resource exhaustion\n* Fixed the [CVE-2026-21441](https://scout.docker.com/vulnerabilities/id/CVE-2026-21441) vulnerability\n\n#### Amazon Machine Image (AMI)\n\n* Increased the frequency of session updates sent to the Wallarm Cloud. Sessions now appear in the UI faster, closer to real time\n* Improved memory usage monitoring and prevention of resource exhaustion\n* Fixed the [CVE-2026-21441](https://scout.docker.com/vulnerabilities/id/CVE-2026-21441) vulnerability"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.18",
    "line": "5.x",
    "date": "2025-12-26",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#5318-2025-12-26",
    "body_markdown": "#### All-in-one installer\n\n* Fixed an issue where malformed fuzzing traffic could cause NGINX crashes, as observed in logs\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed an issue where malformed fuzzing traffic could cause NGINX crashes, as observed in logs"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.8.1",
    "line": "6.x",
    "date": "2025-12-24",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#681-2025-12-24",
    "body_markdown": "#### All-in-one installer\n\n* Fixed an issue where malformed fuzzing traffic could cause NGINX crashes, as observed in logs\n* Added API token masking in Node logs to prevent sensitive data exposure\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed an issue where malformed fuzzing traffic could cause NGINX crashes, as observed in logs\n* Added API token masking in Node logs to prevent sensitive data exposure\n\n#### Helm chart for Sidecar\n\n* Fixed an issue where malformed fuzzing traffic could cause NGINX crashes, as observed in logs\n* Added API token masking in Node logs to prevent sensitive data exposure\n\n#### NGINX-based Docker image\n\n* Fixed an issue where malformed fuzzing traffic could cause NGINX crashes, as observed in logs\n* Added API token masking in Node logs to prevent sensitive data exposure\n\n#### Amazon Machine Image (AMI)\n\n* Fixed an issue where malformed fuzzing traffic could cause NGINX crashes, as observed in logs\n* Added API token masking in Node logs to prevent sensitive data exposure"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.8.0",
    "line": "6.x",
    "date": "2025-12-23",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#680-2025-12-23",
    "body_markdown": "#### All-in-one installer\n\n* Bug fixes:\n    * Fixed the issue where integers were not being masked when using the [\"Mask sensitive data\" rule](../user-guides/rules/sensitive-data-rule.md)\n    * Fixed the issue where responses containing infoleak stamps were being blocked. Wallarm no longer blocks such responses, as doing so caused false detections and prevented rules from being edited\n    * Fixed the issue where the [`wallarm_status` service statistics](../admin-en/configure-statistics-service.md) contained the outdated [`abnormal` metric](../admin-en/configure-statistics-service.md#usage), which was incorrectly increasing with each request. The metric and other outdated fields have been removed\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Bug fixes:\n    * Fixed the issue where integers were not being masked when using the [\"Mask sensitive data\" rule](../user-guides/rules/sensitive-data-rule.md)\n    * Fixed the issue where responses containing infoleak stamps were being blocked. Wallarm no longer blocks such responses, as doing so caused false detections and prevented rules from being edited\n    * Fixed the issue where the [`wallarm_status` service statistics](../admin-en/configure-statistics-service.md) contained the outdated [`abnormal` metric](../admin-en/configure-statistics-service.md#usage), which was incorrectly increasing with each request. The metric and other outdated fields have been removed\n\n#### Helm chart for Sidecar\n\n* Bug fixes:\n    * Fixed the issue where integers were not being masked when using the [\"Mask sensitive data\" rule](../user-guides/rules/sensitive-data-rule.md)\n    * Fixed an issue where large or overlapping denylisted IP ranges were not being blocked in Security Edge-hosted environments\n    * Fixed the issue where responses containing infoleak stamps were being blocked. Wallarm no longer blocks such responses, as doing so caused false detections and prevented rules from being edited\n    * Fixed the issue where the [`wallarm_status` service statistics](../admin-en/configure-statistics-service.md) contained the outdated [`abnormal` metric](../admin-en/configure-statistics-service.md#usage), which was incorrectly increasing with each request. The metric and other outdated fields have been removed\n\n#### NGINX-based Docker image\n\n* Bug fixes:\n    * Fixed the issue where integers were not being masked when using the [\"Mask sensitive data\" rule](../user-guides/rules/sensitive-data-rule.md)\n    * Fixed the issue where responses containing infoleak stamps were being blocked. Wallarm no longer blocks such responses, as doing so caused false detections and prevented rules from being edited\n    * Fixed the issue where the [`wallarm_status` service statistics](../admin-en/configure-statistics-service.md) contained the outdated [`abnormal` metric](../admin-en/configure-statistics-service.md#usage), which was incorrectly increasing with each request. The metric and other outdated fields have been removed\n\n#### Amazon Machine Image (AMI)\n\n* Bug fixes:\n    * Fixed the issue where integers were not being masked when using the [\"Mask sensitive data\" rule](../user-guides/rules/sensitive-data-rule.md)\n    * Fixed the issue where responses containing infoleak stamps were being blocked. Wallarm no longer blocks such responses, as doing so caused false detections and prevented rules from being edited\n    * Fixed the issue where the [`wallarm_status` service statistics](../admin-en/configure-statistics-service.md) contained the outdated [`abnormal` metric](../admin-en/configure-statistics-service.md#usage), which was incorrectly increasing with each request. The metric and other outdated fields have been removed"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.7.3",
    "line": "6.x",
    "date": "2025-12-11",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#673-2025-12-11",
    "body_markdown": "#### All-in-one installer\n\n* Fixed an issue where large or overlapping denylisted IP ranges were not being blocked in Security Edge-hosted environments\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed an issue where large or overlapping denylisted IP ranges were not being blocked in Security Edge-hosted environments\n\n#### NGINX-based Docker image\n\n* Fixed an issue where large or overlapping denylisted IP ranges were not being blocked in Security Edge-hosted environments\n\n#### Amazon Machine Image (AMI)\n\n* Fixed an issue where large or overlapping denylisted IP ranges were not being blocked in Security Edge-hosted environments"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.7.1",
    "line": "6.x",
    "date": "2025-11-17",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#671-2025-11-17",
    "body_markdown": "#### All-in-one installer\n\n* Fixed `'error: no error'` when processing gRPC/WebSocket response attacks\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed YAML indentation issue causing Helm deployment to fail when postanalytics was configured as a DaemonSet\n* Fixed `'error: no error'` when processing gRPC/WebSocket response attacks\n\n#### Helm chart for Sidecar\n\n* Fixed `'error: no error'` when processing gRPC/WebSocket response attacks\n\n#### NGINX-based Docker image\n\n* Fixed `'error: no error'` when processing gRPC/WebSocket response attacks\n\n#### Amazon Machine Image (AMI)\n\n* Node installation now requires that no system user named `wallarm` exists\n* Introduced JA4 fingerprinting in the [NGINX node](../installation/nginx-native-node-internals.md#nginx-node)\n\n    JA4 fingerprints help detect threats and malicious clients based on TLS handshake characteristics. JA4 fingerprints are used as an additional factor when deciding to block a request.\n\n    The feature is disabled by default. To enable it, add the following [NGINX directive](../admin-en/configure-parameters-en.md#wallarm_fingerprint) inside the `http` or `server` block:\n    \n    ```\n    wallarm_fingerprint on;\n    ```\n    \n* Introduced the `wallarm_fingerprint_ja4_raw` and `wallarm_fingerprint_ja4` variables to [configure extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node) when JA4 fingerprinting is enabled\n* Improved Node initialization logs — added detailed information about component type, supported versions, error source, API endpoint, and Node UUID to simplify troubleshooting during the initialization stage\n* Fixed the [CVE-2025-58188](https://www.cve.org/CVERecord?id=CVE-2025-58188) vulnerability\n* Fixed the issue where the Node raised an error when a JWT token was sent in the `Authorization: Bearer` header\n* Fixed invalid type error when editing automatically created rules for attacks detected in gRPC responses\n* Fixed `'error: no error'` when processing gRPC/WebSocket response attacks"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.7.0",
    "line": "6.x",
    "date": "2025-11-05",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#670-2025-11-05",
    "body_markdown": "#### All-in-one installer\n\n* Node installation now requires that no system user named `wallarm` exists\n* Added support for Ubuntu 25.10 (Questing Quokka)\n* Added support for CentOS 10 Stream\n* Added support for Oracle Linux 10.x\n* Added support for NGINX mainline 1.29.2 and 1.29.3\n* Updated AlmaLinux 9 support to include the latest package updates\n* Introduced JA4 fingerprinting in the [NGINX node](../installation/nginx-native-node-internals.md#nginx-node)\n\n    JA4 fingerprints help detect threats and malicious clients based on TLS handshake characteristics. JA4 fingerprints are used as an additional factor when deciding to block a request.\n\n    The feature is disabled by default. To enable it, add the following [NGINX directive](../admin-en/configure-parameters-en.md#wallarm_fingerprint) inside the `http` or `server` block:\n    \n    ```\n    wallarm_fingerprint on;\n    ```\n    \n* Introduced the `wallarm_fingerprint_ja4_raw` and `wallarm_fingerprint_ja4` variables to [configure extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node) when JA4 fingerprinting is enabled\n* Improved Node initialization logs — added detailed information about component type, supported versions, error source, API endpoint, and Node UUID to simplify troubleshooting during the initialization stage\n* Fixed the [CVE-2025-58188](https://www.cve.org/CVERecord?id=CVE-2025-58188) vulnerability\n* Fixed the issue where the Node raised an error when a JWT token was sent in the `Authorization: Bearer` header\n* Fixed invalid type error when editing automatically created rules for attacks detected in gRPC responses\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Updated Community Ingress NGINX Controller 1.11.8 support to align with the latest upstream updates\n* Introduced JA4 fingerprinting in the [NGINX node](../installation/nginx-native-node-internals.md#nginx-node)\n\n    JA4 fingerprints help detect threats and malicious clients based on TLS handshake characteristics. JA4 fingerprints are used as an additional factor when deciding to block a request.\n\n    The feature is disabled by default. To enable it, add the following [NGINX directive](../admin-en/configure-parameters-en.md#wallarm_fingerprint) inside the `http` or `server` block:\n    \n    ```\n    wallarm_fingerprint on;\n    ```\n    \n* Introduced the `wallarm_fingerprint_ja4_raw` and `wallarm_fingerprint_ja4` variables to [configure extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node) when JA4 fingerprinting is enabled\n* Improved Node initialization logs — added detailed information about component type, supported versions, error source, API endpoint, and Node UUID to simplify troubleshooting during the initialization stage\n* Updated default values for **wcli** Controller metrics:\n\n    * [`controller.wallarm.wcliPostanalytics.metrics.enabled : true`](../admin-en/configure-kubernetes-en.md#controllerwallarmwclipostanalyticsmetricsenabled)\n    * [`controller.wallarm.wcliPostanalytics.metrics.port : 9003`](../admin-en/configure-kubernetes-en.md#controllerwallarmwclipostanalyticsmetricsport)\n    * [`controller.wallarm.wcliPostanalytics.metrics.host : \":9003\"`](../admin-en/configure-kubernetes-en.md#controllerwallarmwclipostanalyticsmetricshost)\n\n* Switched to native HTTP readiness and liveness probes for the **wstore** component\n* Fixed the following vulnerabilities:\n\n    * [CVE-2025-58187](https://nvd.nist.gov/vuln/detail/CVE-2025-58187)\n    * [CVE-2025-58188](https://www.cve.org/CVERecord?id=CVE-2025-58188)\n    * [CVE-2025-31498](https://nvd.nist.gov/vuln/detail/CVE-2025-31498)\n* Fixed the issue where the Node raised an error when a JWT token was sent in the `Authorization: Bearer` header\n* Fixed invalid type error when editing automatically created rules for attacks detected in gRPC responses\n\n#### Helm chart for Sidecar\n\n* Introduced JA4 fingerprinting in the [NGINX node](../installation/nginx-native-node-internals.md#nginx-node)\n\n    JA4 fingerprints help detect threats and malicious clients based on TLS handshake characteristics. JA4 fingerprints are used as an additional factor when deciding to block a request.\n\n    The feature is disabled by default. To enable it, add the following [NGINX directive](../admin-en/configure-parameters-en.md#wallarm_fingerprint) inside the `http` or `server` block:\n    \n    ```\n    wallarm_fingerprint on;\n    ```\n    \n* Introduced the `wallarm_fingerprint_ja4_raw` and `wallarm_fingerprint_ja4` variables to [configure extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node) when JA4 fingerprinting is enabled\n* Improved Node initialization logs — added detailed information about component type, supported versions, error source, API endpoint, and Node UUID to simplify troubleshooting during the initialization stage\n* Fixed the [CVE-2025-58188](https://www.cve.org/CVERecord?id=CVE-2025-58188) vulnerability\n* Fixed the issue where the Node raised an error when a JWT token was sent in the `Authorization: Bearer` header\n* Fixed invalid type error when editing automatically created rules for attacks detected in gRPC responses\n\n#### NGINX-based Docker image\n\n* Introduced JA4 fingerprinting in the [NGINX node](../installation/nginx-native-node-internals.md#nginx-node)\n\n    JA4 fingerprints help detect threats and malicious clients based on TLS handshake characteristics. JA4 fingerprints are used as an additional factor when deciding to block a request.\n\n    The feature is disabled by default. To enable it, add the following [NGINX directive](../admin-en/configure-parameters-en.md#wallarm_fingerprint) inside the `http` or `server` block:\n    \n    ```\n    wallarm_fingerprint on;\n    ```\n    \n* Introduced the `wallarm_fingerprint_ja4_raw` and `wallarm_fingerprint_ja4` variables to [configure extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node) when JA4 fingerprinting is enabled\n* Improved Node initialization logs — added detailed information about component type, supported versions, error source, API endpoint, and Node UUID to simplify troubleshooting during the initialization stage\n* Fixed the [CVE-2025-58188](https://www.cve.org/CVERecord?id=CVE-2025-58188) vulnerability\n* Fixed the issue where the Node raised an error when a JWT token was sent in the `Authorization: Bearer` header\n* Fixed invalid type error when editing automatically created rules for attacks detected in gRPC responses"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.6.2",
    "line": "6.x",
    "date": "2025-10-16",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#662-2025-10-16",
    "body_markdown": "#### Helm chart for Wallarm NGINX Ingress controller\n\n* Introduced support for OpenAPI 3.1 in the [API Specification Enforcement](../api-specification-enforcement/overview.md) feature — you can now upload specifications in version 3.1 format to compare traffic against them, identify mismatches, and mitigate related security risks\n* Fixed the following vulnerabilities:\n    \n    * [CVE-2025-49796](https://nvd.nist.gov/vuln/detail/cve-2025-49796)\n    * [CVE-2025-49794](https://nvd.nist.gov/vuln/detail/cve-2025-49794)\n    * [CVE-2025-6021](https://nvd.nist.gov/vuln/detail/cve-2025-6021)\n    * [CVE-2025-49795](https://nvd.nist.gov/vuln/detail/cve-2025-49795)\n    * [CVE-2025-6170](https://nvd.nist.gov/vuln/detail/cve-2025-6170)"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.6.1",
    "line": "6.x",
    "date": "2025-10-16",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#661-2025-10-16",
    "body_markdown": "#### All-in-one installer\n\n* Introduced support for OpenAPI 3.1 in the [API Specification Enforcement](../api-specification-enforcement/overview.md) feature — you can now upload specifications in version 3.1 format to compare traffic against them, identify mismatches, and mitigate related security risks\n* Fixed the following vulnerabilities:\n    \n    * [CVE-2025-49796](https://nvd.nist.gov/vuln/detail/cve-2025-49796)\n    * [CVE-2025-49794](https://nvd.nist.gov/vuln/detail/cve-2025-49794)\n    * [CVE-2025-6021](https://nvd.nist.gov/vuln/detail/cve-2025-6021)\n    * [CVE-2025-49795](https://nvd.nist.gov/vuln/detail/cve-2025-49795)\n    * [CVE-2025-6170](https://nvd.nist.gov/vuln/detail/cve-2025-6170)\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed the postanalytics (wstore) liveness probe to align with the `serviceProtocol` setting\n\n    When `serviceProtocol` is set to `tcp4`, the probe now explicitly uses IPv4, preventing restarts for dual-stack/IPv6 clusters.\n\n#### Helm chart for Sidecar\n\n* Introduced support for OpenAPI 3.1 in the [API Specification Enforcement](../api-specification-enforcement/overview.md) feature — you can now upload specifications in version 3.1 format to compare traffic against them, identify mismatches, and mitigate related security risks\n* Fixed the following vulnerabilities:\n    \n    * [CVE-2025-49796](https://nvd.nist.gov/vuln/detail/cve-2025-49796)\n    * [CVE-2025-49794](https://nvd.nist.gov/vuln/detail/cve-2025-49794)\n    * [CVE-2025-6021](https://nvd.nist.gov/vuln/detail/cve-2025-6021)\n    * [CVE-2025-49795](https://nvd.nist.gov/vuln/detail/cve-2025-49795)\n    * [CVE-2025-6170](https://nvd.nist.gov/vuln/detail/cve-2025-6170)\n\n#### NGINX-based Docker image\n\n* Introduced support for OpenAPI 3.1 in the [API Specification Enforcement](../api-specification-enforcement/overview.md) feature — you can now upload specifications in version 3.1 format to compare traffic against them, identify mismatches, and mitigate related security risks\n* Fixed the following vulnerabilities:\n    \n    * [CVE-2025-49796](https://nvd.nist.gov/vuln/detail/cve-2025-49796)\n    * [CVE-2025-49794](https://nvd.nist.gov/vuln/detail/cve-2025-49794)\n    * [CVE-2025-6021](https://nvd.nist.gov/vuln/detail/cve-2025-6021)\n    * [CVE-2025-49795](https://nvd.nist.gov/vuln/detail/cve-2025-49795)\n    * [CVE-2025-6170](https://nvd.nist.gov/vuln/detail/cve-2025-6170)\n\n#### Amazon Machine Image (AMI)\n\n* Introduced support for OpenAPI 3.1 in the [API Specification Enforcement](../api-specification-enforcement/overview.md) feature — you can now upload specifications in version 3.1 format to compare traffic against them, identify mismatches, and mitigate related security risks\n* Fixed the following vulnerabilities:\n    \n    * [CVE-2025-49796](https://nvd.nist.gov/vuln/detail/cve-2025-49796)\n    * [CVE-2025-49794](https://nvd.nist.gov/vuln/detail/cve-2025-49794)\n    * [CVE-2025-6021](https://nvd.nist.gov/vuln/detail/cve-2025-6021)\n    * [CVE-2025-49795](https://nvd.nist.gov/vuln/detail/cve-2025-49795)\n    * [CVE-2025-6170](https://nvd.nist.gov/vuln/detail/cve-2025-6170)"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.6.0",
    "line": "6.x",
    "date": "2025-10-03",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#660-2025-10-03",
    "body_markdown": "#### All-in-one installer\n\n* Changed the default **wstore** binding to IPv4 (`tcp4`), it now listens only on IPv4 instead of dual‑stack\n\n    If your configuration uses `localhost` for **wstore**, update it to `127.0.0.1`.\n* Introduced protocol selection (tcp, tcp4, tcp6) using the `WALLARM_WSTORE__SERVICE__PROTOCOL` environment variable, which can be set in `/opt/wallarm/env.list`\n\n    The default value is `\"tcp4\"`.\n* Fixed an issue where response context parameters configured in API Sessions were not uploaded to the Wallarm Cloud\n* Introduced a new Prometheus metric [`wallarm_wcli_job_export_period`](../admin-en/wcli-metrics.md#wallarm_wcli_job_export_period) to track the average export delay for each wcli job (e.g., `reqexp`, `blkexp`, `botexp`)\n* Introduced a new `$wallarm_mode` variable for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    This variable returns the final filtration mode applied to a malicious request, taking into account both local settings and those from the Wallarm Cloud (e.g., rules and mitigation controls) with their prioritization.\n* Updated the wording on the [Wallarm-branded block page](../admin-en/configuration-guides/configure-block-page-and-code.md), the page now looks as follows:\n\n    ![Wallarm blocking page](../images/configuration-guides/blocking-page-provided-by-wallarm-6.x.png)\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Changed the default **wstore** binding to IPv4 (`tcp4`), it now listens only on IPv4 instead of dual‑stack\n* Introduced protocol selection (tcp, tcp4, tcp6) in Ingress values ([`controller.wallarm.postanalytics.serviceProtocol`](../admin-en/configure-kubernetes-en.md#controllerwallarmpostanalyticsserviceprotocol))\n\n    The default value is `\"tcp4\"`.\n* Changed the default value of [`controller.wallarm.postanalytics.serviceAddress`](../admin-en/configure-kubernetes-en.md#controllerwallarmpostanalyticsserviceaddress) to `\"0.0.0.0:3313\"`\n    \n    This allows IPv4 traffic only. If you are using a custom value, make sure it matches the selected `controller.wallarm.postanalytics.serviceProtocol`.\n* Fixed an issue where response context parameters configured in API Sessions were not uploaded to the Wallarm Cloud\n* Introduced a new Prometheus metric `wallarm_wcli_job_export_lag` to track the average export delay for each wcli job (e.g., `reqexp`, `blkexp`, `botexp`)\n* Introduced a new `wallarm_mode` variable for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    This variable returns the final filtration mode applied to a malicious request, taking into account both local settings and those from the Wallarm Cloud (e.g., rules and mitigation controls) with their prioritization.\n* Updated the wording on the [Wallarm-branded block page](../admin-en/configuration-guides/configure-block-page-and-code.md), the page now looks as follows:\n\n    ![Wallarm blocking page](../images/configuration-guides/blocking-page-provided-by-wallarm-6.x.png)\n* Fixed the following vulnerabilities:\n\n    * [CVE-2025-9230](https://nvd.nist.gov/vuln/detail/CVE-2025-9230)\n    * [CVE-2025-9231](https://nvd.nist.gov/vuln/detail/CVE-2025-9231)\n    * [CVE-2025-9232](https://nvd.nist.gov/vuln/detail/CVE-2025-9232)\n    * [CVE-2025-50181](https://nvd.nist.gov/vuln/detail/CVE-2025-50181)\n    * [CVE-2025-50182](https://nvd.nist.gov/vuln/detail/CVE-2025-50182)\n    * [CVE-2024-47081](https://nvd.nist.gov/vuln/detail/CVE-2025-47081)\n    * [CVE-2025-9086](https://nvd.nist.gov/vuln/detail/CVE-2025-9086)\n    * [CVE-2025-10148](https://nvd.nist.gov/vuln/detail/CVE-2025-10148)\n    * [CVE-2025-22872](https://nvd.nist.gov/vuln/detail/CVE-2025-22872)\n\n#### Helm chart for Sidecar\n\n* Changed the default **wstore** binding to IPv4 (`tcp4`), it now listens only on IPv4 instead of dual‑stack\n* Introduced protocol selection (tcp, tcp4, tcp6) in Ingress values ([`postanalytics.wstore.config.serviceProtocol`](../installation/kubernetes/sidecar-proxy/helm-chart-for-wallarm.md#postanalyticswstoreconfigserviceprotocol))\n\n    The default value is `\"tcp4\"`.\n* Changed the default value of [`postanalytics.wstore.config.serviceAddress`](../installation/kubernetes/sidecar-proxy/helm-chart-for-wallarm.md#postanalyticswstoreconfigserviceaddress) to `\"0.0.0.0:3313\"`\n    \n    This allows IPv4 traffic only. If you are using a custom value, make sure it matches the selected `postanalytics.wstore.config.serviceProtocol`.\n* Fixed an issue where response context parameters configured in API Sessions were not uploaded to the Wallarm Cloud\n* Introduced a new Prometheus metric `wallarm_wcli_job_export_lag` to track the average export delay for each wcli job (e.g., `reqexp`, `blkexp`, `botexp`)\n* Introduced a new `$wallarm_mode` variable for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    This variable returns the final filtration mode applied to a malicious request, taking into account both local settings and those from the Wallarm Cloud (e.g., rules and mitigation controls) with their prioritization.\n* Updated the wording on the [Wallarm-branded block page](../admin-en/configuration-guides/configure-block-page-and-code.md), the page now looks as follows:\n\n    ![Wallarm blocking page](../images/configuration-guides/blocking-page-provided-by-wallarm-6.x.png)\n* Fixed the following vulnerabilities:\n\n    * [CVE-2025-9230](https://nvd.nist.gov/vuln/detail/CVE-2025-9230)\n    * [CVE-2025-9231](https://nvd.nist.gov/vuln/detail/CVE-2025-9231)\n    * [CVE-2025-9232](https://nvd.nist.gov/vuln/detail/CVE-2025-9232)\n    * [CVE-2025-50181](https://nvd.nist.gov/vuln/detail/CVE-2025-50181)\n    * [CVE-2025-50182](https://nvd.nist.gov/vuln/detail/CVE-2025-50182)\n    * [CVE-2024-47081](https://nvd.nist.gov/vuln/detail/CVE-2025-47081)\n    * [CVE-2025-9086](https://nvd.nist.gov/vuln/detail/CVE-2025-9086)\n    * [CVE-2025-10148](https://nvd.nist.gov/vuln/detail/CVE-2025-10148)\n\n#### NGINX-based Docker image\n\n* Changed the default **wstore** binding to IPv4 (`tcp4`), it now listens only on IPv4 instead of dual‑stack\n\n    If your configuration uses `localhost` for **wstore**, update it to `127.0.0.1`.\n* Introduced protocol selection (tcp, tcp4, tcp6) via the `WALLARM_WSTORE__SERVICE__PROTOCOL` environment variable\n\n    The default value is `\"tcp4\"`.\n* Fixed an issue where response context parameters configured in API Sessions were not uploaded to the Wallarm Cloud\n* Introduced a new Prometheus metric `wallarm_wcli_job_export_lag` to track the average export delay for each wcli job (e.g., `reqexp`, `blkexp`, `botexp`)\n* Fixed an issue where Docker container logs showed a false error about inability to connect to port 3313 when `upstream wallarm_wstore` was configured with `localhost` instead of `127.0.0.1`\n\n    False error example:\n\n    ```\n    2025/09/11 15:49:07 [error] 33#33: wallarm: [::1]:3313 connect() failed 21\n    ```\n* Introduced a new `$wallarm_mode` variable for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    This variable returns the final filtration mode applied to a malicious request, taking into account both local settings and those from the Wallarm Cloud (e.g., rules and mitigation controls) with their prioritization.\n* Included an [SBOM](../integrations-devsecops/generate-sbom-for-docker-images.md) in the image by default, you can retrieve it using the following command:\n\n    ```\n    docker sbom wallarm/node:6.6.1\n    ```\n* Updated the wording on the [Wallarm-branded block page](../admin-en/configuration-guides/configure-block-page-and-code.md), the page now looks as follows:\n\n    ![Wallarm blocking page](../images/configuration-guides/blocking-page-provided-by-wallarm-6.x.png)\n* Fixed the following vulnerabilities:\n\n    * [CVE-2025-9230](https://nvd.nist.gov/vuln/detail/CVE-2025-9230)\n    * [CVE-2025-9231](https://nvd.nist.gov/vuln/detail/CVE-2025-9231)\n    * [CVE-2025-9232](https://nvd.nist.gov/vuln/detail/CVE-2025-9232)\n    * [CVE-2025-50181](https://nvd.nist.gov/vuln/detail/CVE-2025-50181)\n    * [CVE-2025-50182](https://nvd.nist.gov/vuln/detail/CVE-2025-50182)\n    * [CVE-2024-47081](https://nvd.nist.gov/vuln/detail/CVE-2025-47081)\n    * [CVE-2025-59375](https://nvd.nist.gov/vuln/detail/CVE-2025-59375)\n    * [CVE-2025-8961](https://nvd.nist.gov/vuln/detail/CVE-2025-8961)\n    * [CVE-2025-9165](https://nvd.nist.gov/vuln/detail/CVE-2025-9165)\n\n#### Amazon Machine Image (AMI)\n\n* Changed the default **wstore** binding to IPv4 (`tcp4`), it now listens only on IPv4 instead of dual‑stack\n\n    If your configuration uses `localhost` for **wstore**, update it to `127.0.0.1`.\n* Introduced protocol selection (tcp, tcp4, tcp6) using the `WALLARM_WSTORE__SERVICE__PROTOCOL` environment variable, which can be set in `/opt/wallarm/env.list`\n\n    The default value is `\"tcp4\"`.\n* Fixed an issue where response context parameters configured in API Sessions were not uploaded to the Wallarm Cloud\n* Introduced a new Prometheus metric `wallarm_wcli_job_export_lag` to track the average export delay for each wcli job (e.g., `reqexp`, `blkexp`, `botexp`)\n* Introduced a new `$wallarm_mode` variable for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    This variable returns the final filtration mode applied to a malicious request, taking into account both local settings and those from the Wallarm Cloud (e.g., rules and mitigation controls) with their prioritization.\n* Updated the wording on the [Wallarm-branded block page](../admin-en/configuration-guides/configure-block-page-and-code.md), the page now looks as follows:\n\n    ![Wallarm blocking page](../images/configuration-guides/blocking-page-provided-by-wallarm-6.x.png)"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.5.1",
    "line": "6.x",
    "date": "2025-09-09",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#651-2025-09-09",
    "body_markdown": "#### All-in-one installer\n\n* Added support for [blocking attackers by API sessions](../api-sessions/blocking.md)\n* Added support for NGINX Plus R35\n* Exposed [**wcli** Controller metrics endpoint](../admin-en/wcli-metrics.md) for external monitoring\n* Relaxed content-type validation in [API Specification Enforcement](../api-specification-enforcement/overview.md): requests with image MIME types (`image/png`, `image/jpeg`, `image/gif`, `image/webp`, `image/avif`, `image/heic`, `image/heif`, `image/bmp`, `image/tiff`, `image/svg+xml`) are no longer rejected\n* Bumped Go version to 1.24\n* Fixed the behavior of the [`wallarm_wstore_throttle_mode`](../admin-en/wstore-metrics.md#wallarm_wstore_throttle_mode) Prometheus metric, which previously did not return to the normal state (`0`) after throttling ended\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added support for [blocking attackers by API sessions](../api-sessions/blocking.md)\n* Added [Prometheus metrics support](../admin-en/apifw-metrics.md) for API Specification Enforcement service operation (based on the built-in API Firewall service)\n\n    Metrics are disabled by default and can be enabled through the new [`controller.wallarm.apiFirewall.metrics.*`](../admin-en/configure-kubernetes-en.md#controllerwallarmapifirewallmetrics) values.\n* Exposed [**wcli** Controller metrics endpoint](../admin-en/wcli-metrics.md) for external monitoring\n* Relaxed content-type validation in [API Specification Enforcement](../api-specification-enforcement/overview.md): requests with image MIME types (`image/png`, `image/jpeg`, `image/gif`, `image/webp`, `image/avif`, `image/heic`, `image/heif`, `image/bmp`, `image/tiff`, `image/svg+xml`) are no longer rejected\n* Bumped Go version to 1.24\n* Fixed the behavior of the [`wallarm_wstore_throttle_mode`](../admin-en/wstore-metrics.md#wallarm_wstore_throttle_mode) Prometheus metric, which previously did not return to the normal state (`0`) after throttling ended\n* Upgraded to Community Ingress NGINX Controller version 1.11.8, aligning with the upstream Helm chart version 4.11.8 and Alpine version 3.22.0\n* Fixed the [CVE-2025-5399](https://nvd.nist.gov/vuln/detail/CVE-2025-5399) and [CVE-2025-22872](https://nvd.nist.gov/vuln/detail/CVE-2025-22872) vulnerabilities due to the upstream upgrade\n\n#### Helm chart for Sidecar\n\n* Added support for [blocking attackers by API sessions](../api-sessions/blocking.md)\n* Added [Prometheus metrics support](../admin-en/apifw-metrics.md) for API Specification Enforcement service operation (based on the built-in API Firewall service)\n\n    Metrics are disabled by default and can be enabled through the new [`config.wallarm.apiFirewall.metrics.*`](../installation/kubernetes/sidecar-proxy/helm-chart-for-wallarm.md) values.\n* Exposed [**wcli** Controller metrics endpoint](../admin-en/wcli-metrics.md) for external monitoring\n* Relaxed content-type validation in [API Specification Enforcement](../api-specification-enforcement/overview.md): requests with image MIME types (`image/png`, `image/jpeg`, `image/gif`, `image/webp`, `image/avif`, `image/heic`, `image/heif`, `image/bmp`, `image/tiff`, `image/svg+xml`) are no longer rejected\n* Bumped Go version to 1.24\n* Fixed the behavior of the [`wallarm_wstore_throttle_mode`](../admin-en/wstore-metrics.md#wallarm_wstore_throttle_mode) Prometheus metric, which previously did not return to the normal state (`0`) after throttling ended\n\n#### NGINX-based Docker image\n\n* Added support for [blocking attackers by API sessions](../api-sessions/blocking.md)\n* Exposed [**wcli** Controller metrics endpoint](../admin-en/wcli-metrics.md) for external monitoring\n* Relaxed content-type validation in [API Specification Enforcement](../api-specification-enforcement/overview.md): requests with image MIME types (`image/png`, `image/jpeg`, `image/gif`, `image/webp`, `image/avif`, `image/heic`, `image/heif`, `image/bmp`, `image/tiff`, `image/svg+xml`) are no longer rejected\n* Bumped Go version to 1.24\n* Fixed the behavior of the [`wallarm_wstore_throttle_mode`](../admin-en/wstore-metrics.md#wallarm_wstore_throttle_mode) Prometheus metric, which previously did not return to the normal state (`0`) after throttling ended\n\n#### Amazon Machine Image (AMI)\n\n* Added support for [blocking attackers by API sessions](../api-sessions/blocking.md)\n* Exposed [**wcli** Controller metrics endpoint](../admin-en/wcli-metrics.md) for external monitoring\n* Relaxed content-type validation in [API Specification Enforcement](../api-specification-enforcement/overview.md): requests with image MIME types (`image/png`, `image/jpeg`, `image/gif`, `image/webp`, `image/avif`, `image/heic`, `image/heif`, `image/bmp`, `image/tiff`, `image/svg+xml`) are no longer rejected\n* Bumped Go version to 1.24\n* Fixed the behavior of the [`wallarm_wstore_throttle_mode`](../admin-en/wstore-metrics.md#wallarm_wstore_throttle_mode) Prometheus metric, which previously did not return to the normal state (`0`) after throttling ended"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.17",
    "line": "5.x",
    "date": "2025-08-20",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#5317-2025-08-20",
    "body_markdown": "#### All-in-one installer\n\n* Relaxed content-type validation in [API Specification Enforcement](../api-specification-enforcement/overview.md): requests with image MIME types (`image/png`, `image/jpeg`, `image/gif`, `image/webp`, `image/avif`, `image/heic`, `image/heif`, `image/bmp`, `image/tiff`, `image/svg+xml`) are no longer rejected\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Relaxed content-type validation in [API Specification Enforcement](../api-specification-enforcement/overview.md): requests with image MIME types (`image/png`, `image/jpeg`, `image/gif`, `image/webp`, `image/avif`, `image/heic`, `image/heif`, `image/bmp`, `image/tiff`, `image/svg+xml`) are no longer rejected\n\n#### Helm chart for Sidecar\n\n* Relaxed content-type validation in [API Specification Enforcement](../api-specification-enforcement/overview.md): requests with image MIME types (`image/png`, `image/jpeg`, `image/gif`, `image/webp`, `image/avif`, `image/heic`, `image/heif`, `image/bmp`, `image/tiff`, `image/svg+xml`) are no longer rejected\n\n#### NGINX-based Docker image\n\n* Relaxed content-type validation in [API Specification Enforcement](../api-specification-enforcement/overview.md): requests with image MIME types (`image/png`, `image/jpeg`, `image/gif`, `image/webp`, `image/avif`, `image/heic`, `image/heif`, `image/bmp`, `image/tiff`, `image/svg+xml`) are no longer rejected"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.4.1",
    "line": "6.x",
    "date": "2025-08-07",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#641-2025-08-07",
    "body_markdown": "#### All-in-one installer\n\n* Added [Prometheus metrics support](../admin-en/apifw-metrics.md) for API Specification Enforcement service operation (based on the built-in API Firewall service):\n\n    * Enable with `APIFW_METRICS_ENABLED=true` in `/opt/wallarm/env.list`\n    * Default endpoint: `:9010/metrics`\n    * Host and endpoint name configurable via variables `APIFW_METRICS_HOST` and `APIFW_METRICS_ENDPOINT_NAME`\n\n#### NGINX-based Docker image\n\n* Added [Prometheus metrics support](../admin-en/apifw-metrics.md) for API Specification Enforcement service operation (based on the built-in API Firewall service):\n\n    * Enable with the environment variable `APIFW_METRICS_ENABLED=true`\n    * Default endpoint: `:9010/metrics`\n    * Expose the metrics port in your container (e.g., for the default state, use `-p 9010:9010`)\n    * Host and endpoint name configurable via variables `APIFW_METRICS_HOST` and `APIFW_METRICS_ENDPOINT_NAME`"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.4.0",
    "line": "6.x",
    "date": "2025-07-31",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#640-2025-07-31",
    "body_markdown": "#### All-in-one installer\n\n* Introduced a new `wallarm_block_reason` variable for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    This variable adds information to the log on the reason for request blocking (detected attack, part of bot activity, denylist, etc.)\n* Introduced the new [`wallarm_export_streams`](../admin-en/configure-parameters-en.md#wallarm_export_streams) Wallarm directive which controls whether the Node exports information about long-lived streaming connections to the internal postanalytics storage (wstore)\n\n    By default, `wallarm_export_streams` is set to `off`. When enabled, the Node sends stream and message data to wstore, allowing [API Discovery](../api-discovery/overview.md) to build the API inventory and display gRPC/WebSocket endpoints in the Wallarm Console UI.\n* Fixed the stuffed credentials export to the Cloud\n* Improved GraphQL parser\n* Bug fixes and internal improvements\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Introduced a new `wallarm_block_reason` variable for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    This variable adds information to the log on the reason for request blocking (detected attack, part of bot activity, denylist, etc.)\n* Introduced the new [`wallarm_export_streams`](../admin-en/configure-parameters-en.md#wallarm_export_streams) Wallarm directive which controls whether the Node exports information about long-lived streaming connections to the internal postanalytics storage (wstore)\n\n    By default, `wallarm_export_streams` is set to `off`. When enabled, the Node sends stream and message data to wstore, allowing [API Discovery](../api-discovery/overview.md) to build the API inventory and display gRPC/WebSocket endpoints in the Wallarm Console UI.\n* Fixed the stuffed credentials export to the Cloud\n* Improved GraphQL parser\n* Bug fixes and internal improvements\n\n#### Helm chart for Sidecar\n\n* Introduced a new `wallarm_block_reason` variable for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    This variable adds information to the log on the reason for request blocking (detected attack, part of bot activity, denylist, etc.)\n* Introduced the new [`wallarm_export_streams`](../admin-en/configure-parameters-en.md#wallarm_export_streams) Wallarm directive which controls whether the Node exports information about long-lived streaming connections to the internal postanalytics storage (wstore)\n\n    By default, `wallarm_export_streams` is set to `off`. When enabled, the Node sends stream and message data to wstore, allowing [API Discovery](../api-discovery/overview.md) to build the API inventory and display gRPC/WebSocket endpoints in the Wallarm Console UI.\n* Fixed the stuffed credentials export to the Cloud\n* Improved GraphQL parser\n* Bug fixes and internal improvements\n\n#### NGINX-based Docker image\n\n* Introduced a new `wallarm_block_reason` variable for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    This variable adds information to the log on the reason for request blocking (detected attack, part of bot activity, denylist, etc.)\n* Introduced the new [`wallarm_export_streams`](../admin-en/configure-parameters-en.md#wallarm_export_streams) Wallarm directive which controls whether the Node exports information about long-lived streaming connections to the internal postanalytics storage (wstore)\n\n    By default, `wallarm_export_streams` is set to `off`. When enabled, the Node sends stream and message data to wstore, allowing [API Discovery](../api-discovery/overview.md) to build the API inventory and display gRPC/WebSocket endpoints in the Wallarm Console UI.\n* Fixed the stuffed credentials export to the Cloud\n* Improved GraphQL parser\n* Bug fixes and internal improvements\n\n#### Amazon Machine Image (AMI)\n\n* Introduced a new `wallarm_block_reason` variable for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    This variable adds information to the log on the reason for request blocking (detected attack, part of bot activity, denylist, etc.)\n* Introduced the new [`wallarm_export_streams`](../admin-en/configure-parameters-en.md#wallarm_export_streams) Wallarm directive which controls whether the Node exports information about long-lived streaming connections to the internal postanalytics storage (wstore)\n\n    By default, `wallarm_export_streams` is set to `off`. When enabled, the Node sends stream and message data to wstore, allowing [API Discovery](../api-discovery/overview.md) to build the API inventory and display gRPC/WebSocket endpoints in the Wallarm Console UI.\n* Fixed the stuffed credentials export to the Cloud\n* Improved GraphQL parser\n* Bug fixes and internal improvements"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.3.1",
    "line": "6.x",
    "date": "2025-07-23",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#631-2025-07-23",
    "body_markdown": "#### All-in-one installer\n\n* Fixed memory leak\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed memory leak\n\n#### Helm chart for Sidecar\n\n* Fixed memory leak\n\n#### NGINX-based Docker image\n\n* Fixed memory leak\n\n#### Amazon Machine Image (AMI)\n\n* Fixed memory leak"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.3.0",
    "line": "6.x",
    "date": "2025-07-08",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#630-2025-07-08",
    "body_markdown": "#### All-in-one installer\n\n* Added support for [file upload restriction policy](../api-protection/file-upload-restriction.md) via mitigation controls\n* Added support for [unrestricted resource consumption](../attacks-vulns-list.md#unrestricted-resource-consumption) mitigation by [API Abuse Prevention](../api-abuse-prevention/overview.md)\n* In rules, the separator used in [**xml_tag**](../user-guides/rules/request-processing.md#xml) values that combine a URI, namespace, and tag name has been changed from `:` to `|`\n* Internal improvements\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added support for [file upload restriction policy](../api-protection/file-upload-restriction.md) via mitigation controls\n* Added support for [unrestricted resource consumption](../attacks-vulns-list.md#unrestricted-resource-consumption) mitigation by [API Abuse Prevention](../api-abuse-prevention/overview.md)\n* Added the [`validation.forbidDangerousAnnotations`](../admin-en/configure-kubernetes-en.md#validationforbiddangerousannotations) chart value to toggle the CEL rule that blocks the dangerous `server-snippet` and `configuration-snippet` annotations\n\n    By default, it is set to `false` - dangerous annotations are not blocked.\n\n    Behavior in Node 6.2.0- is unchanged (annotations are blocked by default when `validation.enableCel` is `true`).\n* Added support for the [`controller.wallarm.postanalytics.serviceAddress`](../admin-en/configure-kubernetes-en.md#controllerwallarmpostanalyticsserviceaddress) parameter to customize the address and port for incoming **wstore** connections\n* In rules, the separator used in [**xml_tag**](../user-guides/rules/request-processing.md#xml) values that combine a URI, namespace, and tag name has been changed from `:` to `|`\n* Internal improvements\n\n#### Helm chart for Sidecar\n\n* Added support for [file upload restriction policy](../api-protection/file-upload-restriction.md) via mitigation controls\n* Added support for [unrestricted resource consumption](../attacks-vulns-list.md#unrestricted-resource-consumption) mitigation by [API Abuse Prevention](../api-abuse-prevention/overview.md)\n* Added support for the [`postanalytics.wstore.config.serviceAddress`](../installation/kubernetes/sidecar-proxy/helm-chart-for-wallarm.md#postanalyticswstoreconfigserviceaddress) parameter to customize the address and port for incoming **wstore** connections\n* In rules, the separator used in [**xml_tag**](../user-guides/rules/request-processing.md#xml) values that combine a URI, namespace, and tag name has been changed from `:` to `|`\n* Internal improvements\n\n#### NGINX-based Docker image\n\n* Added support for [file upload restriction policy](../api-protection/file-upload-restriction.md) via mitigation controls\n* Added support for [unrestricted resource consumption](../attacks-vulns-list.md#unrestricted-resource-consumption) mitigation by [API Abuse Prevention](../api-abuse-prevention/overview.md)\n* In rules, the separator used in [**xml_tag**](../user-guides/rules/request-processing.md#xml) values that combine a URI, namespace, and tag name has been changed from `:` to `|`\n* Internal improvements\n\n#### Amazon Machine Image (AMI)\n\n* Added support for [file upload restriction policy](../api-protection/file-upload-restriction.md) via mitigation controls\n* Added support for [unrestricted resource consumption](../attacks-vulns-list.md#unrestricted-resource-consumption) mitigation by [API Abuse Prevention](../api-abuse-prevention/overview.md)\n* In rules, the separator used in [**xml_tag**](../user-guides/rules/request-processing.md#xml) values that combine a URI, namespace, and tag name has been changed from `:` to `|`\n* Internal improvements"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.2.1",
    "line": "6.x",
    "date": "2025-06-23",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#621-2025-06-23",
    "body_markdown": "#### All-in-one installer\n\n* Minor internal file structure change"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.16",
    "line": "5.x",
    "date": "2025-06-23",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#5316-2025-06-23",
    "body_markdown": "#### All-in-one installer\n\n* Fixed the [CVE-2025-22874](https://nvd.nist.gov/vuln/detail/CVE-2025-22874) vulnerability\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed the [CVE-2025-22874](https://nvd.nist.gov/vuln/detail/CVE-2025-22874) vulnerability\n\n#### Helm chart for Sidecar\n\n* Fixed the [CVE-2025-22874](https://nvd.nist.gov/vuln/detail/CVE-2025-22874) vulnerability\n* Bump Alpine version to 3.22\n* Upgrade NGINX to version 1.28.0\n\n#### NGINX-based Docker image\n\n* Fixed the [CVE-2025-22874](https://nvd.nist.gov/vuln/detail/CVE-2025-22874) vulnerability\n* Bump Alpine version to 3.22\n* Upgrade NGINX to version 1.28.0"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.2.0",
    "line": "6.x",
    "date": "2025-06-20",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#620-2025-06-20",
    "body_markdown": "#### All-in-one installer\n\n* Added support for [mitigation control-based](../api-protection/graphql-rule.md#mitigation-control-based-protection) **GraphQL API Protection**\n* Optimized stream handling for gRPC traffic\n* Added the `streams` and `messages` parameters to the [`/wallarm-status` service](../admin-en/configure-statistics-service.md) output to report the number of processed gRPC/WebSocket streams and messages\n* Added support for [SSL/TLS and mTLS](../admin-en/installation-postanalytics-en.md#ssltls-and-mtls-between-the-nginx-wallarm-module-and-the-postanalytics-module) between the NGINX-Wallarm module and the postanalytics module when they are installed separately\n* Fixed [wstore](../admin-en/wstore-metrics.md#metrics-endpoint) ports binding: now bound to `127.0.0.1` instead of `0.0.0.0`\n* Minor bug fixes\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added support for [mitigation control-based](../api-protection/graphql-rule.md#mitigation-control-based-protection) **GraphQL API Protection**\n* Optimized stream handling for gRPC traffic\n* Optimized stream handling for gRPC traffic\n* Added the `streams` and `messages` parameters to the [`/wallarm-status` service](../admin-en/configure-statistics-service.md) output to report the number of processed gRPC/WebSocket streams and messages\n* Added support for [SSL/TLS and mTLS](../admin-en/configure-kubernetes-en.md#controllerwallarmpostanalyticstls) between the Filtering Node and the postanalytics module\n* Split the unified `controller.wallarm.wcli` component in `values.yaml` into 2 separately [configurable units](../admin-en/configure-kubernetes-en.md): `wcliController` and `wcliPostanalytics`, allowing fine-grained control over containers\n* Minor bug fixes\n\n#### Helm chart for Sidecar\n\n* Added support for [mitigation control-based](../api-protection/graphql-rule.md#mitigation-control-based-protection) **GraphQL API Protection**\n* Optimized stream handling for gRPC traffic\n* Optimized stream handling for gRPC traffic\n* Added support for [SSL/TLS and mTLS](../installation/kubernetes/sidecar-proxy/helm-chart-for-wallarm.md#postanalyticswstoretls) between the Filtering Node and the postanalytics module\n* Bump Alpine version to 3.22\n* Upgrade NGINX to version 1.28.0\n* Minor bug fixes\n\n#### NGINX-based Docker image\n\n* Added support for [mitigation control-based](../api-protection/graphql-rule.md#mitigation-control-based-protection) **GraphQL API Protection**\n* Optimized stream handling for gRPC traffic\n* Optimized stream handling for gRPC traffic\n* Added the `streams` and `messages` parameters to the [`/wallarm-status` service](../admin-en/configure-statistics-service.md) output to report the number of processed gRPC/WebSocket streams and messages\n* Added support for [SSL/TLS and mTLS](../admin-en/installation-postanalytics-en.md#ssltls-and-mtls-between-the-nginx-wallarm-module-and-the-postanalytics-module) between the NGINX-Wallarm module and the postanalytics module when they are installed separately\n* Fixed [wstore](../admin-en/wstore-metrics.md#metrics-endpoint) ports binding: now bound to `127.0.0.1` instead of `0.0.0.0`\n* Bump Alpine version to 3.22\n* Upgrade NGINX to version 1.28.0\n* Minor bug fixes\n\n#### Amazon Machine Image (AMI)\n\n* Added support for [mitigation control-based](../api-protection/graphql-rule.md#mitigation-control-based-protection) **GraphQL API Protection**\n* Optimized stream handling for gRPC traffic\n* Optimized stream handling for gRPC traffic\n* Added the `streams` and `messages` parameters to the [`/wallarm-status` service](../admin-en/configure-statistics-service.md) output to report the number of processed gRPC/WebSocket streams and messages\n* Added support for [SSL/TLS and mTLS](../admin-en/installation-postanalytics-en.md#ssltls-and-mtls-between-the-nginx-wallarm-module-and-the-postanalytics-module) between the NGINX-Wallarm module and the postanalytics module when they are installed separately\n* Fixed [wstore](../admin-en/wstore-metrics.md#metrics-endpoint) ports binding: now bound to `127.0.0.1` instead of `0.0.0.0`\n* Minor bug fixes"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.15",
    "line": "5.x",
    "date": "2025-06-04",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#5315-2025-06-04",
    "body_markdown": "#### All-in-one installer\n\n* Fixed the [CVE-2025-47273](https://nvd.nist.gov/vuln/detail/CVE-2025-47273) vulnerability\n* Removed support for the `WALLARM_ATTACKS_DETAILED_EXPORT` environment variable which has been used to disable exporting full attack data to Wallarm Cloud\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed the [CVE-2025-47273](https://nvd.nist.gov/vuln/detail/CVE-2025-47273) vulnerability\n\n#### Helm chart for Sidecar\n\n* Fixed the [CVE-2025-47273](https://nvd.nist.gov/vuln/detail/CVE-2025-47273) vulnerability\n\n#### NGINX-based Docker image\n\n* Fixed the [CVE-2025-47273](https://nvd.nist.gov/vuln/detail/CVE-2025-47273) vulnerability\n* Removed support for the `WALLARM_ATTACKS_DETAILED_EXPORT` environment variable which has been used to disable exporting full attack data to Wallarm Cloud\n\n#### Amazon Machine Image (AMI)\n\n* Fixed the [CVE-2025-47273](https://nvd.nist.gov/vuln/detail/CVE-2025-47273) vulnerability"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.14",
    "line": "5.x",
    "date": "2025-05-26",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#5314-2025-05-26",
    "body_markdown": "#### All-in-one installer\n\n* Added support for the `WALLARM_ATTACKS_DETAILED_EXPORT` environment variable to optionally disable exporting full attack data to Wallarm Cloud\n\n    This is intended for environments with strict data protection requirements.\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* The number of specification violations that can be detected in a single request during API Specification Enforcement is limited to `3` to provide sufficient insight into policy violations while maintaining optimal Node performance\n\n    If needed, you can [adjust the value](../api-specification-enforcement/setup.md#increasing-the-number-of-detected-specification-violations).\n* Added the [`validation.enableCel`](../admin-en/configure-kubernetes-en.md#validationenablecel) parameter to enable validation of Ingress resources via Validating Admission Policies\n\n#### NGINX-based Docker image\n\n* Added support for the `WALLARM_ATTACKS_DETAILED_EXPORT` environment variable to optionally disable exporting full attack data to Wallarm Cloud\n\n    This is intended for environments with strict data protection requirements."
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.1.0",
    "line": "6.x",
    "date": "2025-05-09",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#610-2025-05-09",
    "body_markdown": "#### All-in-one installer\n\n* Added support for [**enumeration**](../api-protection/enumeration-attack-protection.md) mitigation controls\n* Added support for [**DoS protection**](../api-protection/dos-protection.md) mitigation control\n* Bugfix: Attacks originating from allowlisted sources are no longer shown in the **Attacks** section\n* wstore logs now include `\"component\": \"wstore\"` for easier identification\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Bugfix: Attacks originating from allowlisted sources are no longer shown in the **Attacks** section\n* wstore logs now include `\"component\": \"wstore\"` for easier identification\n\n#### Helm chart for Sidecar\n\n* Bugfix: Attacks originating from allowlisted sources are no longer shown in the **Attacks** section\n* wstore logs now include `\"component\": \"wstore\"` for easier identification\n\n#### NGINX-based Docker image\n\n* Bugfix: Attacks originating from allowlisted sources are no longer shown in the **Attacks** section\n* wstore logs now include `\"component\": \"wstore\"` for easier identification\n\n#### Amazon Machine Image (AMI)\n\n* Bugfix: Attacks originating from allowlisted sources are no longer shown in the **Attacks** section\n* wstore logs now include `\"component\": \"wstore\"` for easier identification"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.0.3",
    "line": "6.x",
    "date": "2025-05-07",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#603-2025-05-07",
    "body_markdown": "#### All-in-one installer\n\n* Added support for Amazon Linux 2\n* Fixed the installation issues with custom NGINX"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.0.2",
    "line": "6.x",
    "date": "2025-04-29",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#602-2025-04-29",
    "body_markdown": "#### All-in-one installer\n\n* Added support for NGINX stable 1.28.0\n* Added support for NGINX mainline 1.27.5\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added the [`validation.enableCel`](../admin-en/configure-kubernetes-en.md#validationenablecel) parameter to enable validation of Ingress resources via Validating Admission Policies"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.13",
    "line": "5.x",
    "date": "2025-04-29",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#5313-2025-04-29",
    "body_markdown": "#### All-in-one installer\n\n* Added support for NGINX stable 1.28.0\n* Added support for NGINX mainline 1.27.5\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed the [CVE-2025-22871](https://nvd.nist.gov/vuln/detail/CVE-2025-22871), [CVE-2025-31115](https://nvd.nist.gov/vuln/detail/CVE-2025-31115), [CVE-2025-31498](https://nvd.nist.gov/vuln/detail/CVE-2025-31498) vulnerabilities\n\n#### Helm chart for Sidecar\n\n* The number of specification violations that can be detected in a single request during API Specification Enforcement is limited to `3` to provide sufficient insight into policy violations while maintaining optimal Node performance\n\n    If needed, you can [adjust the value](../api-specification-enforcement/setup.md#increasing-the-number-of-detected-specification-violations)."
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.12",
    "line": "5.x",
    "date": "2025-04-25",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#5312-2025-04-24",
    "body_markdown": "#### All-in-one installer\n\n* The number of specification violations that can be detected in a single request during API Specification Enforcement is limited to `3` to provide sufficient insight into policy violations while maintaining optimal Node performance\n\n    If needed, you can [adjust the value](../api-specification-enforcement/setup.md#increasing-the-number-of-detected-specification-violations).\n* Fixed the [CVE-2024-56406](https://nvd.nist.gov/vuln/detail/CVE-2024-56406), [CVE-2025-31115](https://nvd.nist.gov/vuln/detail/CVE-2025-31115), [CVE-2025-22871](https://nvd.nist.gov/vuln/detail/CVE-2025-22871) vulnerabilities\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed the [CVE-2024-55549](https://nvd.nist.gov/vuln/detail/CVE-2024-55549), [CVE-2025-24855](https://nvd.nist.gov/vuln/detail/CVE-2025-24855), [CVE-2025-30153](https://nvd.nist.gov/vuln/detail/CVE-2025-30153), [CVE-2025-30204](https://nvd.nist.gov/vuln/detail/CVE-2025-30204), [CVE-2024-8176](https://nvd.nist.gov/vuln/detail/CVE-2024-8176), [CVE-2025-29914](https://nvd.nist.gov/vuln/detail/CVE-2025-29914), [CVE-2025-23419](https://nvd.nist.gov/vuln/detail/CVE-2025-23419), [CVE-2025-22870](https://nvd.nist.gov/vuln/detail/CVE-2025-22870), [CVE-2025-27113](https://nvd.nist.gov/vuln/detail/CVE-2025-27113) vulnerabilities\n\n#### Helm chart for Sidecar\n\n* Fixed the [CVE-2024-56406](https://nvd.nist.gov/vuln/detail/CVE-2024-56406), [CVE-2025-31115](https://nvd.nist.gov/vuln/detail/CVE-2025-31115), [CVE-2025-22871](https://nvd.nist.gov/vuln/detail/CVE-2025-22871) vulnerabilities\n\n#### NGINX-based Docker image\n\n* The number of specification violations that can be detected in a single request during API Specification Enforcement is limited to `3` to provide sufficient insight into policy violations while maintaining optimal Node performance\n\n    If needed, you can [adjust the value](../api-specification-enforcement/setup.md#increasing-the-number-of-detected-specification-violations).\n* Fixed the [CVE-2024-56406](https://nvd.nist.gov/vuln/detail/CVE-2024-56406), [CVE-2025-31115](https://nvd.nist.gov/vuln/detail/CVE-2025-31115), [CVE-2025-22871](https://nvd.nist.gov/vuln/detail/CVE-2025-22871) vulnerabilities\n\n#### Amazon Machine Image (AMI)\n\n* The number of specification violations that can be detected in a single request during API Specification Enforcement is limited to `3` to provide sufficient insight into policy violations while maintaining optimal Node performance\n\n    If needed, you can [adjust the value](../api-specification-enforcement/setup.md#increasing-the-number-of-detected-specification-violations).\n* Fixed the [CVE-2024-56406](https://nvd.nist.gov/vuln/detail/CVE-2024-56406), [CVE-2025-31115](https://nvd.nist.gov/vuln/detail/CVE-2025-31115), [CVE-2025-22871](https://nvd.nist.gov/vuln/detail/CVE-2025-22871) vulnerabilities"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.0.1",
    "line": "6.x",
    "date": "2025-04-22",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#601-2025-04-22",
    "body_markdown": "#### All-in-one installer\n\n* Fixed the [CVE-2024-56406](https://nvd.nist.gov/vuln/detail/CVE-2024-56406), [CVE-2025-31115](https://nvd.nist.gov/vuln/detail/CVE-2025-31115) vulnerabilities\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed the [CVE-2025-22871](https://nvd.nist.gov/vuln/detail/CVE-2025-22871) vulnerability\n\n#### Helm chart for Sidecar\n\n* Fixed the [CVE-2024-56406](https://nvd.nist.gov/vuln/detail/CVE-2024-56406), [CVE-2025-31115](https://nvd.nist.gov/vuln/detail/CVE-2025-31115) vulnerabilities\n\n#### NGINX-based Docker image\n\n* Fixed the [CVE-2024-56406](https://nvd.nist.gov/vuln/detail/CVE-2024-56406), [CVE-2025-31115](https://nvd.nist.gov/vuln/detail/CVE-2025-31115) vulnerabilities\n\n#### Amazon Machine Image (AMI)\n\n* Fixed the [CVE-2024-56406](https://nvd.nist.gov/vuln/detail/CVE-2024-56406), [CVE-2025-31115](https://nvd.nist.gov/vuln/detail/CVE-2025-31115) vulnerabilities"
  },
  {
    "artifact_id": "nginx-node",
    "version": "6.0.0",
    "line": "6.x",
    "date": "2025-04-03",
    "url": "https://docs.wallarm.com/updating-migrating/node-artifact-versions/#600-2025-04-03",
    "body_markdown": "#### All-in-one installer\n\n* Initial release 6.0, [see changelog](what-is-new.md)\n* Added support for NGINX Plus R34\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Initial release 6.0, [see changelog](what-is-new.md)\n\n#### Helm chart for Sidecar\n\n* Initial release 6.0, [see changelog](what-is-new.md)\n\n#### NGINX-based Docker image\n\n* Initial release 6.0, [see changelog](what-is-new.md)\n\n#### Amazon Machine Image (AMI)\n\n* Initial release 6.0, [see changelog](what-is-new.md)"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.11",
    "line": "5.x",
    "date": "2025-04-03",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#5311-2025-04-03",
    "body_markdown": "#### All-in-one installer\n\n* Fixed the [CVE-2024-55549](https://nvd.nist.gov/vuln/detail/CVE-2024-55549), [CVE-2025-24855](https://nvd.nist.gov/vuln/detail/CVE-2025-24855), [CVE-2025-30153](https://nvd.nist.gov/vuln/detail/CVE-2025-30153), [CVE-2025-30204](https://nvd.nist.gov/vuln/detail/CVE-2025-30204), [CVE-2024-8176](https://nvd.nist.gov/vuln/detail/CVE-2024-8176), [CVE-2025-29914](https://nvd.nist.gov/vuln/detail/CVE-2025-29914), [CVE-2025-23419](https://nvd.nist.gov/vuln/detail/CVE-2025-23419), [CVE-2025-22870](https://nvd.nist.gov/vuln/detail/CVE-2025-22870), [CVE-2025-27113](https://nvd.nist.gov/vuln/detail/CVE-2025-27113) vulnerabilities\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Upgraded to Community Ingress NGINX Controller version 1.11.5, aligning with the upstream Helm chart version 4.11.5\n* Fixed the critical [CVE-2025-1974](https://nvd.nist.gov/vuln/detail/CVE-2025-1974) vulnerability due to the upstream upgrade\n\n#### Helm chart for Sidecar\n\n* Fixed the [CVE-2024-55549](https://nvd.nist.gov/vuln/detail/CVE-2024-55549), [CVE-2025-24855](https://nvd.nist.gov/vuln/detail/CVE-2025-24855), [CVE-2025-30153](https://nvd.nist.gov/vuln/detail/CVE-2025-30153), [CVE-2025-30204](https://nvd.nist.gov/vuln/detail/CVE-2025-30204), [CVE-2024-8176](https://nvd.nist.gov/vuln/detail/CVE-2024-8176), [CVE-2025-29914](https://nvd.nist.gov/vuln/detail/CVE-2025-29914), [CVE-2025-23419](https://nvd.nist.gov/vuln/detail/CVE-2025-23419), [CVE-2025-22870](https://nvd.nist.gov/vuln/detail/CVE-2025-22870), [CVE-2025-27113](https://nvd.nist.gov/vuln/detail/CVE-2025-27113) vulnerabilities\n\n#### NGINX-based Docker image\n\n* Fixed the [CVE-2024-55549](https://nvd.nist.gov/vuln/detail/CVE-2024-55549), [CVE-2025-24855](https://nvd.nist.gov/vuln/detail/CVE-2025-24855), [CVE-2025-30153](https://nvd.nist.gov/vuln/detail/CVE-2025-30153), [CVE-2025-30204](https://nvd.nist.gov/vuln/detail/CVE-2025-30204), [CVE-2024-8176](https://nvd.nist.gov/vuln/detail/CVE-2024-8176), [CVE-2025-29914](https://nvd.nist.gov/vuln/detail/CVE-2025-29914), [CVE-2025-23419](https://nvd.nist.gov/vuln/detail/CVE-2025-23419), [CVE-2025-22870](https://nvd.nist.gov/vuln/detail/CVE-2025-22870), [CVE-2025-27113](https://nvd.nist.gov/vuln/detail/CVE-2025-27113) vulnerabilities"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.10",
    "line": "5.x",
    "date": "2025-03-12",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#5310-2025-03-10",
    "body_markdown": "#### All-in-one installer\n\n* Added support for NGINX stable 1.26.3\n* Added support for NGINX mainline 1.27.4\n* Fixed the [CVE-2024-56171](https://nvd.nist.gov/vuln/detail/CVE-2024-56171), [CVE-2025-24928](https://nvd.nist.gov/vuln/detail/CVE-2025-24928), [CVE-2025-22869](https://nvd.nist.gov/vuln/detail/CVE-2025-22869), [CVE-2025-22868](https://nvd.nist.gov/vuln/detail/CVE-2025-22868) vulnerabilities\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed the [CVE-2024-56171](https://nvd.nist.gov/vuln/detail/CVE-2024-56171), [CVE-2025-24928](https://nvd.nist.gov/vuln/detail/CVE-2025-24928), [CVE-2025-22869](https://nvd.nist.gov/vuln/detail/CVE-2025-22869), [CVE-2025-22868](https://nvd.nist.gov/vuln/detail/CVE-2025-22868) vulnerabilities\n\n#### Helm chart for Sidecar\n\n* Fixed the [CVE-2024-56171](https://nvd.nist.gov/vuln/detail/CVE-2024-56171), [CVE-2025-24928](https://nvd.nist.gov/vuln/detail/CVE-2025-24928), [CVE-2025-22869](https://nvd.nist.gov/vuln/detail/CVE-2025-22869), [CVE-2025-22868](https://nvd.nist.gov/vuln/detail/CVE-2025-22868) vulnerabilities\n\n#### NGINX-based Docker image\n\n* Fixed the [CVE-2024-56171](https://nvd.nist.gov/vuln/detail/CVE-2024-56171), [CVE-2025-24928](https://nvd.nist.gov/vuln/detail/CVE-2025-24928), [CVE-2025-22869](https://nvd.nist.gov/vuln/detail/CVE-2025-22869), [CVE-2025-22868](https://nvd.nist.gov/vuln/detail/CVE-2025-22868) vulnerabilities\n\n#### Amazon Machine Image (AMI)\n\n* Fixed the [CVE-2024-56171](https://nvd.nist.gov/vuln/detail/CVE-2024-56171), [CVE-2025-24928](https://nvd.nist.gov/vuln/detail/CVE-2025-24928), [CVE-2025-22869](https://nvd.nist.gov/vuln/detail/CVE-2025-22869), [CVE-2025-22868](https://nvd.nist.gov/vuln/detail/CVE-2025-22868) vulnerabilities"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.9",
    "line": "5.x",
    "date": "2025-02-18",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#539-2025-02-18",
    "body_markdown": "#### Helm chart for Sidecar\n\n* Upgraded to Sidecar controller 1.6.1\n* Fixed the [CVE-2025-26519](https://nvd.nist.gov/vuln/detail/CVE-2025-26519), [CVE-2024-12797](https://nvd.nist.gov/vuln/detail/CVE-2024-12797) and [CVE-2024-13176](https://nvd.nist.gov/vuln/detail/CVE-2024-13176) controller vulnerabilities"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.8",
    "line": "5.x",
    "date": "2025-02-18",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#538-2025-02-18",
    "body_markdown": "#### All-in-one installer\n\n* Fixed the [CVE-2025-26519](https://nvd.nist.gov/vuln/detail/CVE-2025-26519) and [CVE-2024-12797](https://nvd.nist.gov/vuln/detail/CVE-2024-12797) vulnerabilities\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed the [CVE-2025-26519](https://nvd.nist.gov/vuln/detail/CVE-2025-26519) and [CVE-2024-12797](https://nvd.nist.gov/vuln/detail/CVE-2024-12797) vulnerabilities\n\n#### Helm chart for Sidecar\n\n* Fixed the [CVE-2025-26519](https://nvd.nist.gov/vuln/detail/CVE-2025-26519) and [CVE-2024-12797](https://nvd.nist.gov/vuln/detail/CVE-2024-12797) vulnerabilities\n\n#### NGINX-based Docker image\n\n* Fixed the [CVE-2025-26519](https://nvd.nist.gov/vuln/detail/CVE-2025-26519) and [CVE-2024-12797](https://nvd.nist.gov/vuln/detail/CVE-2024-12797) vulnerabilities"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.7",
    "line": "5.x",
    "date": "2025-02-13",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#537-2025-02-04",
    "body_markdown": "#### All-in-one installer\n\n* Added support for the [`WALLARM_APID_ONLY` environment variable](../installation/nginx/all-in-one.md#api-discovery-only-mode) which enables API Discovery-only mode\n\n    In this mode, attacks are blocked locally (if enabled) but not exported to Wallarm Cloud, while [API Discovery](../api-discovery/overview.md), [API session tracking](../api-sessions/overview.md), and [security vulnerability detection](../about-wallarm/detecting-vulnerabilities.md) remain fully functional. This mode is rarely needed, in most environments, using this mode is unnecessary.\n* Fix for the `invalid_xml` attack detection in responses\n* Minor GraphQL parser fixes\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fix for the `invalid_xml` attack detection in responses\n* Minor GraphQL parser fixes\n\n#### Helm chart for Sidecar\n\n* Fix for the `invalid_xml` attack detection in responses\n* Minor GraphQL parser fixes\n\n#### NGINX-based Docker image\n\n* Added support for the `WALLARM_APID_ONLY` environment variable which enables API Discovery-only mode while [running the Docker image](../admin-en/installation-docker-en.md)\n\n    In this mode, attacks are blocked locally (if enabled) but not exported to Wallarm Cloud, while [API Discovery](../api-discovery/overview.md), [API session tracking](../api-sessions/overview.md), and [security vulnerability detection](../about-wallarm/detecting-vulnerabilities.md) remain fully functional. This mode is rarely needed, in most environments, using this mode is unnecessary.\n* Fix for the `invalid_xml` attack detection in responses\n* Minor GraphQL parser fixes\n\n#### Amazon Machine Image (AMI)\n\n* Fix for the `invalid_xml` attack detection in responses\n* Minor GraphQL parser fixes"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.3.0",
    "line": "5.x",
    "date": "2025-01-30",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#530-2025-01-29",
    "body_markdown": "#### All-in-one installer\n\n* Added support for response parameters in [API Sessions](../api-sessions/overview.md) for providing the full context of user activities and more precise [session grouping](../api-sessions/setup.md#session-grouping) (see detailed [change description](../updating-migrating/what-is-new.md#response-parameters-in-api-sessions))\n* Added a full-fledged [GraphQL parser](../user-guides/rules/request-processing.md#gql) (see detailed [change description](../updating-migrating/what-is-new.md#full-fledged-graphql-parser)) that allows:\n\n    * Improved detection of the input validation attacks in GraphQL-specific request points\n    * Fine-tuning attack detection for specific GraphQL points (e.g. disable detection of specific attack types in specific points)\n    * Analyzing specific parts of GraphQL requests in API sessions\n\n* Return RPS and request amount per hosts and origins for Security Edge Inline\n* Fixed invalid time value in serialized requests to properly display the [resource overlimit](../user-guides/rules/configure-overlimit-res-detection.md) attacks\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added support for response parameters in [API Sessions](../api-sessions/overview.md) for providing the full context of user activities and more precise [session grouping](../api-sessions/setup.md#session-grouping) (see detailed [change description](../updating-migrating/what-is-new.md#response-parameters-in-api-sessions))\n* Added a full-fledged [GraphQL parser](../user-guides/rules/request-processing.md#gql) (see detailed [change description](../updating-migrating/what-is-new.md#full-fledged-graphql-parser)) that allows:\n\n    * Improved detection of the input validation attacks in GraphQL-specific request points\n    * Fine-tuning attack detection for specific GraphQL points (e.g. disable detection of specific attack types in specific points)\n    * Analyzing specific parts of GraphQL requests in API sessions\n    \n* Fixed invalid time value in serialized requests to properly display the [resource overlimit](../user-guides/rules/configure-overlimit-res-detection.md) attacks\n\n#### Helm chart for Sidecar\n\n* Added support for response parameters in [API Sessions](../api-sessions/overview.md) for providing the full context of user activities and more precise [session grouping](../api-sessions/setup.md#session-grouping) (see detailed [change description](../updating-migrating/what-is-new.md#response-parameters-in-api-sessions))\n* Added a full-fledged [GraphQL parser](../user-guides/rules/request-processing.md#gql) (see detailed [change description](../updating-migrating/what-is-new.md#full-fledged-graphql-parser)) that allows:\n\n    * Improved detection of the input validation attacks in GraphQL-specific request points\n    * Fine-tuning attack detection for specific GraphQL points (e.g. disable detection of specific attack types in specific points)\n    * Analyzing specific parts of GraphQL requests in API sessions\n    \n* Fixed invalid time value in serialized requests to properly display the [resource overlimit](../user-guides/rules/configure-overlimit-res-detection.md) attacks\n* Added new settings for API Specification Enforcement:\n\n    * `readBufferSize`\n    * `writeBufferSize`\n    * `maxRequestBodySize`\n    * `disableKeepalive`\n    * `maxConnectionsPerIp`\n    * `maxRequestsPerConnection`\n\n    See descriptions and default values [here](../installation/kubernetes/sidecar-proxy/helm-chart-for-wallarm.md#configwallarmapifirewall).\n* Added the [`config.nginx.logs.extended`](../installation/kubernetes/sidecar-proxy/helm-chart-for-wallarm.md#confignginxlogsextended) and [`config.nginx.logs.format`](../installation/kubernetes/sidecar-proxy/helm-chart-for-wallarm.md#confignginxlogsformat) Helm chart values for extended logging in NGINX\n\n#### NGINX-based Docker image\n\n* Added support for response parameters in [API Sessions](../api-sessions/overview.md) for providing the full context of user activities and more precise [session grouping](../api-sessions/setup.md#session-grouping) (see detailed [change description](../updating-migrating/what-is-new.md#response-parameters-in-api-sessions))\n* Added a full-fledged [GraphQL parser](../user-guides/rules/request-processing.md#gql) (see detailed [change description](../updating-migrating/what-is-new.md#full-fledged-graphql-parser)) that allows:\n\n    * Improved detection of the input validation attacks in GraphQL-specific request points\n    * Fine-tuning attack detection for specific GraphQL points (e.g. disable detection of specific attack types in specific points)\n    * Analyzing specific parts of GraphQL requests in API sessions\n    \n* Fixed invalid time value in serialized requests to properly display the [resource overlimit](../user-guides/rules/configure-overlimit-res-detection.md) attacks\n\n#### Amazon Machine Image (AMI)\n\n* Added support for response parameters in [API Sessions](../api-sessions/overview.md) for providing the full context of user activities and more precise [session grouping](../api-sessions/setup.md#session-grouping) (see detailed [change description](../updating-migrating/what-is-new.md#response-parameters-in-api-sessions))\n* Added a full-fledged [GraphQL parser](../user-guides/rules/request-processing.md#gql) (see detailed [change description](../updating-migrating/what-is-new.md#full-fledged-graphql-parser)) that allows:\n\n    * Improved detection of the input validation attacks in GraphQL-specific request points\n    * Fine-tuning attack detection for specific GraphQL points (e.g. disable detection of specific attack types in specific points)\n    * Analyzing specific parts of GraphQL requests in API sessions\n    \n* Fixed invalid time value in serialized requests to properly display the [resource overlimit](../user-guides/rules/configure-overlimit-res-detection.md) attacks"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.2.12",
    "line": "5.x",
    "date": "2025-01-08",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#5212-2025-01-08",
    "body_markdown": "#### Helm chart for Wallarm NGINX Ingress controller\n\n* Resolved the [CVE-2024-45338](https://scout.docker.com/vulnerabilities/id/CVE-2024-45338) controller vulnerability"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.2.11",
    "line": "5.x",
    "date": "2024-12-28",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#5211-2024-12-25",
    "body_markdown": "#### All-in-one installer\n\n* Added support for NGINX Mainline v1.27.2 and 1.27.3\n* Added support for NGINX Plus R33\n* Added support for sensitive business flows in [API Discovery](../api-discovery/sbf.md) and [API Sessions](../api-sessions/exploring.md#sensitive-business-flows)\n* Resolved the [CVE-2024-45337](https://scout.docker.com/vulnerabilities/id/CVE-2024-45337) and [CVE-2024-45338](https://scout.docker.com/vulnerabilities/id/CVE-2024-45338) vulnerabilities\n* Fixed an issue where some requests were processed unsuccessfully, potentially affecting API Sessions, Credential Stuffing, and API Abuse Prevention\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added support for sensitive business flows in [API Discovery](../api-discovery/sbf.md) and [API Sessions](../api-sessions/exploring.md#sensitive-business-flows)\n* Resolved the [CVE-2024-45337](https://scout.docker.com/vulnerabilities/id/CVE-2024-45337) and [CVE-2024-45338](https://scout.docker.com/vulnerabilities/id/CVE-2024-45338) vulnerabilities\n* Fixed an issue where some requests were processed unsuccessfully, potentially affecting API Sessions, Credential Stuffing, and API Abuse Prevention\n\n#### Helm chart for Sidecar\n\n* Added support for sensitive business flows in [API Discovery](../api-discovery/sbf.md) and [API Sessions](../api-sessions/exploring.md#sensitive-business-flows)\n* Resolved the [CVE-2024-45337](https://scout.docker.com/vulnerabilities/id/CVE-2024-45337) and [CVE-2024-45338](https://scout.docker.com/vulnerabilities/id/CVE-2024-45338) vulnerabilities\n* Fixed an issue where some requests were processed unsuccessfully, potentially affecting API Sessions, Credential Stuffing, and API Abuse Prevention\n\n#### NGINX-based Docker image\n\n* Added support for sensitive business flows in [API Discovery](../api-discovery/sbf.md) and [API Sessions](../api-sessions/exploring.md#sensitive-business-flows)\n* Resolved the [CVE-2024-45337](https://scout.docker.com/vulnerabilities/id/CVE-2024-45337) and [CVE-2024-45338](https://scout.docker.com/vulnerabilities/id/CVE-2024-45338) vulnerabilities\n* Fixed an issue where some requests were processed unsuccessfully, potentially affecting API Sessions, Credential Stuffing, and API Abuse Prevention\n\n#### Amazon Machine Image (AMI)\n\n* Added support for sensitive business flows in [API Discovery](../api-discovery/sbf.md) and [API Sessions](../api-sessions/exploring.md#sensitive-business-flows)\n* Resolved the [CVE-2024-45337](https://scout.docker.com/vulnerabilities/id/CVE-2024-45337) and [CVE-2024-45338](https://scout.docker.com/vulnerabilities/id/CVE-2024-45338) vulnerabilities\n* Fixed an issue where some requests were processed unsuccessfully, potentially affecting API Sessions, Credential Stuffing, and API Abuse Prevention"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.2.2",
    "line": "5.x",
    "date": "2024-12-11",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#522-2024-12-11",
    "body_markdown": "#### Helm chart for Wallarm NGINX Ingress controller\n\n* Re-apply the fix for the [GHSA-c5pj-mqfh-rvc3](https://scout.docker.com/vulnerabilities/id/GHSA-c5pj-mqfh-rvc3) vulnerability"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.2.1",
    "line": "5.x",
    "date": "2024-12-09",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#521-2024-12-07",
    "body_markdown": "#### All-in-one installer\n\n* New `$wallarm_attack_point_list` and `$wallarm_attack_stamp_list` variables for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    These variables log request points containing malicious payloads and attack sign IDs, thereby enabling advanced debugging of Node behavior.\n* Minor bug fixes\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Upgraded to Community Ingress NGINX Controller version 1.11.5, aligning with the upstream Helm chart version 4.11.5\n* Breaking changes introduced by the Community Ingress NGINX Controller upgrade:\n\n    * Discontinued support for Opentracing and Zipkin modules, now only supporting Opentelemetry\n    * Dropped support for `PodSecurityPolicy`\n* Compatibility extended up to Kubernetes version 1.30\n* Updated to NGINX 1.25.5\n* Minor bug fixes\n\n#### Helm chart for Sidecar\n\n* New `$wallarm_attack_point_list` and `$wallarm_attack_stamp_list` variables for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    These variables log request points containing malicious payloads and attack sign IDs, thereby enabling advanced debugging of Node behavior.\n* Minor bug fixes\n\n#### NGINX-based Docker image\n\n* New `$wallarm_attack_point_list` and `$wallarm_attack_stamp_list` variables for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    These variables log parameters containing malicious payloads and attack sign IDs enabling advanced debugging of Node behavior.\n* Moved image source and Dockerfile from [GitHub](https://github.com/wallarm/docker-wallarm-node) to an internal GitLab repository\n\n#### Amazon Machine Image (AMI)\n\n* New `$wallarm_attack_point_list` and `$wallarm_attack_stamp_list` variables for [extended logging](../admin-en/configure-logging.md#configuring-extended-logging-for-the-nginxbased-filter-node)\n\n    These variables log parameters containing malicious payloads and attack sign IDs enabling advanced debugging of Node behavior.\n* Minor bug fixes"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.1.1",
    "line": "5.x",
    "date": "2024-11-14",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#511-2024-11-08",
    "body_markdown": "#### All-in-one installer\n\n* Fixed some bugs in the `wallarm-status` service operation\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed the [GHSA-c5pj-mqfh-rvc3](https://scout.docker.com/vulnerabilities/id/GHSA-c5pj-mqfh-rvc3) vulnerability\n* Fixed some bugs in the `wallarm-status` service operation"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.1.0-1",
    "line": "5.x",
    "date": "2024-11-06",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#510-1-2024-11-06",
    "body_markdown": "#### NGINX-based Docker image\n\n* Added support for [API Sessions](../api-sessions/overview.md)\n* [Improved](what-is-new.md#new-in-limiting-request-processing-time) limiting request processing time\n* Reduced memory usage during node registration\n\n#### Amazon Machine Image (AMI)\n\n* Added support for [API Sessions](../api-sessions/overview.md)\n* [Improved](what-is-new.md#new-in-limiting-request-processing-time) limiting request processing time\n* Reduced memory usage during node registration"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.1.0",
    "line": "5.x",
    "date": "2024-11-06",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#510-2024-11-06",
    "body_markdown": "#### All-in-one installer\n\n* Added support for [API Sessions](../api-sessions/overview.md)\n* [Improved](what-is-new.md#new-in-limiting-request-processing-time) limiting request processing time\n* Reduced memory usage during node registration\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added support for [API Sessions](../api-sessions/overview.md)\n* [Improved](what-is-new.md#new-in-limiting-request-processing-time) limiting request processing time\n* Reduced memory usage during node registration\n* Added new settings for API Specification Enforcement:\n\n    * `readBufferSize`\n    * `writeBufferSize`\n    * `maxRequestBodySize`\n    * `disableKeepalive`\n    * `maxConnectionsPerIp`\n    * `maxRequestsPerConnection`\n\n    See descriptions and default values [here](../admin-en/configure-kubernetes-en.md#controllerwallarmapifirewall).\n\n#### Helm chart for Sidecar\n\n* Added support for [API Sessions](../api-sessions/overview.md)\n* [Improved](what-is-new.md#new-in-limiting-request-processing-time) limiting request processing time\n* Reduced memory usage during node registration"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.0.3-1",
    "line": "5.x",
    "date": "2024-10-10",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#503-1-2024-10-10",
    "body_markdown": "#### NGINX-based Docker image\n\n* Added support for [customizing sensitive data detection](../api-discovery/sensitive-data.md#customizing-sensitive-data-detection) in API Discovery\n* Fixed memory leak on duplicate response headers in [libproton](../about-wallarm/protecting-against-attacks.md#basic-set-of-detectors)\n* Fixed memory leak related to IP addresses that are not in [IP lists](../user-guides/ip-lists/overview.md) but have [known source](../user-guides/ip-lists/overview.md#select-object)\n\n#### Amazon Machine Image (AMI)\n\n* Added support for [customizing sensitive data detection](../api-discovery/sensitive-data.md#customizing-sensitive-data-detection) in API Discovery\n* Fixed memory leak on duplicate response headers in [libproton](../about-wallarm/protecting-against-attacks.md#basic-set-of-detectors)\n* Fixed memory leak related to IP addresses that are not in [IP lists](../user-guides/ip-lists/overview.md) but have [known source](../user-guides/ip-lists/overview.md#select-object)"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.0.3",
    "line": "5.x",
    "date": "2024-10-10",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#503-2024-10-10",
    "body_markdown": "#### All-in-one installer\n\n* Added support for [customizing sensitive data detection](../api-discovery/sensitive-data.md#customizing-sensitive-data-detection) in API Discovery\n* Fixed memory leak on duplicate response headers in [libproton](../about-wallarm/protecting-against-attacks.md#basic-set-of-detectors)\n* Fixed memory leak related to IP addresses that are not in [IP lists](../user-guides/ip-lists/overview.md) but have [known source](../user-guides/ip-lists/overview.md#select-object)\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Added support for [customizing sensitive data detection](../api-discovery/sensitive-data.md#customizing-sensitive-data-detection) in API Discovery\n* Fixed memory leak on duplicate response headers in [libproton](../about-wallarm/protecting-against-attacks.md#basic-set-of-detectors)\n* Fixed memory leak related to IP addresses that are not in [IP lists](../user-guides/ip-lists/overview.md) but have [known source](../user-guides/ip-lists/overview.md#select-object)\n\n#### Helm chart for Sidecar\n\n* Added support for [customizing sensitive data detection](../api-discovery/sensitive-data.md#customizing-sensitive-data-detection) in API Discovery\n* Fixed memory leak on duplicate response headers in [libproton](../about-wallarm/protecting-against-attacks.md#basic-set-of-detectors)\n* Fixed memory leak related to IP addresses that are not in [IP lists](../user-guides/ip-lists/overview.md) but have [known source](../user-guides/ip-lists/overview.md#select-object)"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.0.2-1",
    "line": "5.x",
    "date": "2024-09-19",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#502-1-2024-09-18",
    "body_markdown": "#### NGINX-based Docker image\n\n* Fixed installation failure issue when no WAAP + API Security subscription is activated\n* Fixed delays in attack export\n\n#### Amazon Machine Image (AMI)\n\n* Fixed installation failure issue when no WAAP + API Security subscription is activated\n* Fixed delays in attack export"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.0.2",
    "line": "5.x",
    "date": "2024-09-19",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#502-2024-09-18",
    "body_markdown": "#### All-in-one installer\n\n* Fixed installation failure issue when no WAAP + API Security subscription is activated\n* Fixed delays in attack export\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Fixed installation failure issue when no WAAP + API Security subscription is activated\n* Fixed delays in attack export\n\n#### Helm chart for Sidecar\n\n* Fixed installation failure issue when no WAAP + API Security subscription is activated\n* Fixed delays in attack export"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.0.1-1",
    "line": "5.x",
    "date": "2024-08-21",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#501-1-2024-08-21",
    "body_markdown": "#### NGINX-based Docker image\n\n* Initial release 5.0, [see changelog](what-is-new.md)\n* Added support for NGINX v1.26.2 stable\n\n#### Amazon Machine Image (AMI)\n\n* Initial release 5.0, [see changelog](what-is-new.md)"
  },
  {
    "artifact_id": "nginx-node",
    "version": "5.0.1",
    "line": "5.x",
    "date": "2024-08-21",
    "url": "https://docs.wallarm.com/5.x/updating-migrating/node-artifact-versions/#501-2024-08-21",
    "body_markdown": "#### All-in-one installer\n\n* Initial release 5.0, [see changelog](what-is-new.md)\n* Added support for NGINX v1.26.2 stable\n\n#### Helm chart for Wallarm NGINX Ingress controller\n\n* Initial release 5.0, [see changelog](what-is-new.md)\n\n#### Helm chart for Sidecar\n\n* Initial release 5.0, [see changelog](what-is-new.md)"
  }
]
