-
GHOSTWIRE v0.4.0 Stable
released this
2026-10-05 06:10:24 +00:00 | 2 commits to main since this releaseSecurity fixes for API tokens and sign-in, and a new Health card.
Changes
- API tokens no longer manage accounts: a full-access token could create a user or reset a password, sign in as that user and so reach backups and two-step sign-in. Users, passwords, API tokens and the "require two-step sign-in" setting now need a signed-in user in the web interface; tokens get HTTP 403 there. Tokens still manage peers, the server, app settings and logs.
- Sign-in can no longer run the server out of memory: every password check takes 64 MiB, and nothing limited how many ran at once. At most two now run at the same time; when 16 sign-ins are already waiting, more get HTTP 429. A sign-in attempt counts toward the lockout before its password is checked, so parallel attempts can't get past it, and IPv6 addresses are locked out by /64.
- New Health card: the public IPv4 and IPv6 addresses lead the card, and every other check is a tile with a plain-word status, the raw setting and, when it fails, what is wrong.
- Dialogs stay visible with password managers: extensions such as Bitwarden that rearrange the page could make a confirmation dialog seem to vanish.
- Peer names in the peers table are plain text instead of underlined links.
Update
Copy the binary for your server to it and run, as root:
chmod +x GHOSTWIRE-v0.4.0-linux-amd64 sudo ./GHOSTWIRE-v0.4.0-linux-amd64 updateUpdate the iOS app too. Its user, password and API token screens moved to the web interface, and older app builds can't open Settings against v0.4.0. For a new installation, use
installinstead ofupdate; see the README.Files
File For GHOSTWIRE-v0.4.0-linux-amd6464-bit x86 servers GHOSTWIRE-v0.4.0-linux-arm6464-bit ARM, e.g. Raspberry Pi OS 64-bit GHOSTWIRE-v0.4.0-linux-armv7Raspberry Pi OS 32-bit SHA256SUMSchecksums: shasum -a 256 -c SHA256SUMSDownloads