<a id="changelog"></a>

# Changelog

## Version 25.07-779

### Object Storage

- **ZSTRG-38286** - Resolved a memory leak in the proxy-server that
  caused the Proxy Virtual Controller to crash.
- **ZSTRG-37739** - Resolved an issue where uploading large objects using
  pre-signed URLs failed with CORS errors after upgrading Object Storage to
  25.07.
- **ZSTRG-38476** - Resolved an issue where CORS preflight (OPTIONS)
  requests received a 403 (SignatureDoesNotMatch) error.

### VPSA Storage Array / VPSA Flash Array

- **ZSTRG-37730** - Upgraded the SMB engine

### Storage Node

- **ZSTRG-38145** - Resolved an error in IPv6 address handling that could
  prevent certificates from being injected into Virtual Controllers.

### Provisioning Portal

- **ZSTRG-38441** - Resolved an issue where the timezone displayed in the
  Software Update Rescheduling form in the Provisioning Portal was
  inconsistent.

### Security

- **ZSTRG-38456,ZSTRG-38457,ZSTRG-38458,ZSTRG-38459** - Upgraded cross cloud
  components to mitigate the following CVEs

## Version 25.07-752

### VPSA Storage Array / VPSA Flash Array

- **ZSTRG-37439** - Security – [CVE-2026-31431](https://www.cve.org/CVERecord?id=CVE-2026-31431)
  (“Copy Fail”) - mitigates the Linux kernel local
  privilege-escalation vulnerability in the algif_aead module on VPSA Storage
  Arrays running Container services.

## Version 25.07-748

### Object Storage

- **ZSTRG-37173,ZSTRG-37039,ZSTRG-36505** - Resolved an issue that could
  cause internal Object Storage processes to fail during certain delete and
  restore operations, improving overall service reliability.
- **ZSTRG-36547,ZSTRG-37154** - Resolved an issue where member user role unexpectedly
  lost delete permissions for containers and objects following an upgrade to
  version 25.07-723.
- **ZSTRG-36747** - Resolved an issue where the Unified Identity Service
  network port was exposed when the service was not enabled.
- **ZSTRG-36579** - Resolved an issue where CORS (Cross-Origin Resource
  Sharing) headers were absent on versioning-enabled containers.
- **ZSTRG-36234** - Resolved an issue where Audit Logs were not delivered to
  the configured target container when SSL termination was disabled.
- **ZSTRG-36761** - Resolved an issue where creating a user with an email
  address already registered in a different account was incorrectly blocked.
- **ZSTRG-36851** - Resolved an issue where Read-Only Cloud Admin administrator
  users were unable to open the Performance Resource Tree in the management
  console.
- **ZSTRG-36907,ZSTRG-35800** - Resolved an issue where multipart-uploaded
  objects were not replicated correctly to the destination container.
- **ZSTRG-37032** - Expired objects are now correctly excluded from
  replication jobs, preventing unnecessary errors in replication logs.

### VPSA Storage Array / VPSA Flash Array

- **ZSTRG-37064** - Fixed an issue where slow internal log processing caused
  VPSA failover to take longer than expected.
- **ZSTRG-33320** - (VPSA Flash Array) Emergency pool management actions are now
  evaluated based on physical capacity (i.e. Volume snapshot deletion,
  new Volume creation, Volume expansion etc.)
- **ZSTRG-36789** - A new `*.zadaravpsa.com` wildcard TLS certificate has
  been issued for VPSA, ensuring continued secure connectivity.

### Security

- **ZSTRG-37098** - Security update addressing critical and high severity
  vulnerabilities across Storage Node, VPSA, and Object Storage components.

## Version 25.07-723

### Object Storage

- **ZSTRG-36252,ZSTRG-36147** - Fixed a regression introduced in a previous
  release that resulted in slower Object Storage management API responses.
- **ZSTRG-36234** - Fixed an issue where Container Audit Logs were not
  delivered to the target container due to disabled SSL termination.

### VPSA Storage Array / VPSA Flash Array

- **ZSTRG-36142** - Fixed an issue where a Docker image could not be created
  on a newly provisioned VPSA.
- **ZSTRG-36168** - Fixed an issue where Remote Discovery between a VPSA
  upgraded to 25.07 and a VPSA running 23.09 stopped working when both VPSAs
  are part of an Active Directory configuration.

### Storage Node

- **ZSTRG-36176,ZSTRG-35847,ZSTRG-36029,ZSTRG-35861** - Storage Node 25.07
  upgrade related fixes.

## Version 25.07-710

### Object Storage

- **ZSTRG-30793** - Introduced container-level replication to a remote Zadara
  Object Storage instance. For configuration details and usage examples,
  refer to the
  [Container replication](https://guides.zadarastorage.com/ngos-guide/latest/ngos-replication.html)
  section of the Object Storage user guide.
- **ZSTRG-33455** - Introduced the Unified Identity service, enabling replication
  of the Object Storage Identity service to a remote Object Storage region.
  Additional configuration guidance is available in the
  [Unified identity](https://guides.zadarastorage.com/ngos-guide/latest/ngos-settings.html#unified-identity)
  section of the Object Storage user guide.
- **ZSTRG-32520** - Introduced a revised Object Storage Controller specification
  with increased CPU and RAM allocation.
- **ZSTRG-35427** - Introduced 24TB HDD support, improving efficiency and cost
  effectiveness for large Object Storage instances.
- **ZSTRG-31202** - Scalability improvement: increased Object Storage support to
  up to 6,000 Object Storage accounts within a single instance.
- **ZSTRG-30429** - Added the ability to set create/delete permissions for a user
  on the account level. For additional information refer to the
  [Managing Permissions](https://guides.zadarastorage.com/ngos-guide/latest/administration-acl.html)
  section in the Object Storage user guide.
- **ZSTRG-35418,ZSTRG-32503** - Fixed an issue where the Content-MD5 HTTP header
  was missing when attempting to set object lock retention. Veeam users
  considering an upgrade to v13 must upgrade their Object Storage instance
  to version 25.07-710 prior to upgrading to v13.
- **ZSTRG-35929** - Renewed the \*.zadarazios.com TLS certificate.
- **ZSTRG-27587** - Fixed an issue in the Object Storage usage report where the
  system provided only 60 days of data. The usage report can now generate
  up to 90 days of account usage data.
- **ZSTRG-35375** - Fixed an issue where setting permissions from the management
  console on a specific container did not populate the full user list.
- **ZSTRG-34792,ZSTRG-34518** - Fixed an issue encountered when attempting to
  delete an expired object.
- **ZSTRG-33753** - Fixed an issue where deleting a member user failed.
- **ZSTRG-33383** - Fixed an issue where versioned expired objects were not
  deleted by the OLCP rule.
- **ZSTRG-32501** - Fixed an issue where setting a custom metadata header
  returned an error.
- **ZSTRG-30897** - Fixed an issue where Object Storage administrators
  (ZIOS_ADMIN) did not receive notifications when members crossed their
  account quotas.

### VPSA Storage Array / VPSA Flash Array

- **ZSTRG-27805** - Added support for 32Gb FC connectivity (with supported
  hardware).
- **ZSTRG-31053** - Upgraded the SMB service engine.
- **ZSTRG-32053** - Added the option to stop a Media Scan from the management
  UI.
- **ZSTRG-30201** - Added monitoring and alerting capabilities for a Remote
  Object Storage endpoint used for Backup to Object Storage. Monitoring can be
  enabled or disabled, with the ability to define the alert frequency.
- **ZSTRG-32794** - Fixed an issue where setting a Group Quota returned an error.
- **ZSTRG-29774** - Removed the Support section section from the management
  user interface
- **ZSTRG-31084** - Active Directory - for new directory integration, automatic
  domain discovery will be disabled (default) in order to avoid wrong detection
  of the available domains.

### Command Center

- **ZSTRG-35548** - Renewed the \*.zadarastorage.com TLS Certificate.
- **ZSTRG-33395** - Added the Backend network protocol used for drives and
  virtual controllers
- **ZSTRG-33460** - Added REST API to control password expiration settings.

### Provisioning Portal

- **ZSTRG-33457** - Cost and Usage Explorer - Introduced a new global service
  via [Zadara’s Global Provisioning Portal](https://manage.zadara.com)
  providing centralized visibility into cost and usage data across all
  environments. For additional information please refer to the service
  [user guide](https://guides.zadara.com/cau-guide/latest/index.html).
- **ZSTRG-29051** – Organization support – Introduced an *Organization* entity
  in [Zadara’s Global Provisioning Portal](https://manage.zadara.com), enabling
  logical management of users and resources within an organization
- **ZSTRG-35548** - Renewed the \*.zadarastorage.com TLS Certificate
- **ZSTRG-30204** - Removed the option to enable FLC (File-Life-Cycle) Index
  during VPSA creation

### Storage Node

- **ZSTRG-9989** - Added support NVMeOF as the cloud backend protocol
- **ZSTRG-25356** - As part of the 25.07 upgrade, the installer updates the
  NVIDIA network interface firmware. Activating the new firmware requires a
  node reboot. Until the reboot is performed, the node will continue to
  operate normally using the existing firmware, and there is no immediate
  requirement to reboot following the upgrade
- **ZSTRG-27637** - Upgrade SCST packages

### Security

- **ZSTRG-34936** - Upgraded cross cloud components to mitigate the following CVEs
