# Release notes: the 1.1 module

Release notes for the 1.1 module line, 1.1.0-beta.1 to 1.1.0+r24: the first releases of the maintained module, before the renumber to 1.15.0 on 2026-06-01.

Canonical URL: https://modpagespeed.com/docs/release-notes-1-1/

The 1.1 line is the first run of the maintained module: 1.1.0-beta.1, the 1.1.0 general-availability release and the package revisions r1 through r24, before the line was renumbered to [1.15.0](https://modpagespeed.com/docs/release-notes-1-15/) on 2026-06-01. Where the module shipped several package revisions within a few days they are grouped into one entry, listed under the lowest revision in the group. Where a release fixes a security problem its entry leads with that, and [Security updates](https://modpagespeed.com/docs/release-notes/#security-updates) lists every fix with the release that carried it. Entries are collapsed, newest first; open a release to read it in place.

## Releases

### **1.1.0+r23–r24** (2026-05-31 – 2026-06-01, module) — Admin console copy and notices updated.

- **Admin console.** Console copy and notices updated.

### **1.1.0+r22** (2026-05-29, module) — Security and reliability hardening release, the result of a dedicated audit pass.

Security and reliability hardening release, the result of a dedicated audit
pass. **Update recommended.**

- Fixed a remotely triggerable crash condition (denial-of-service class) on
  nginx — a defect inherited from the open-source ngx_pagespeed.
- New opt-in `StrictAdminAccess` directive on Apache and nginx: admin,
  statistics, and console access is decided on the validated client IP and
  never on client-controlled headers. (IIS already gates admin access to
  loopback.)
- ASP.NET Core sidecar hardening: admin endpoints bind to loopback, tighter
  configuration-file permissions, and tokens are kept out of logs.
- IIS: two lock-handling fixes and correct IPv6 address reporting.
- Redis: fixed a crash at startup when a database index is configured, and
  reduced per-command overhead (both defects date to the open-source line,
  2017).

### **1.1.0+r18–r21** (2026-05-25 – 2026-05-27, module) — Security update: 13 admin-console dependency advisories cleared (4 high, 9 medium).

- **Reliability.** Cache-library update: Apache graceful restarts no longer
  leak scoreboard slots, and `nginx -s reload` no longer hangs — both were
  process-lifecycle defects in cache teardown.
- **Security.** Admin-console dependency updates clearing 13 published
  advisories (4 high, 9 medium).
- **Packaging.** The signed apt/yum repositories for the nginx module go GA,
  with per-distro builds pinned to each distro's stock nginx and blocking
  load, symbol, and optimization smoke gates. The EasyApache 4 configuration
  now degrades gracefully if the module file is absent instead of breaking
  Apache startup.

### **1.1.0+r9–r17** (2026-05-21 – 2026-05-22, module) — IIS quality wave (r12–r17 contain no product changes).

IIS quality wave (r12–r17 contain no product changes). **Update recommended
for IIS deployments.**

- Fixed crashes in the IIS URL fetcher and in lock handling.
- Admin endpoints are default-deny in the shipped sample configurations, and
  the module logs a warning when an admin handler receives a non-loopback
  request.
- Smoother installation: per-site cache and log directories are auto-created
  with safe permissions (new `AutoCreateLogDir` directive), initialization
  failures surface as specific `X-Pagespeed-Init-Status` values with
  per-failure error pages, and the MSI grants the required ACLs.
- Upgrading from IISpeed: an existing `iiswebspeed.config` is picked up
  automatically when no `pagespeed.config` is present.

### **1.1.0+r1–r8** (2026-05-19 – 2026-05-21, module) — Packaging and distribution (most of these revisions contain no product changes).

Packaging and distribution (most of these revisions contain no product
changes).

- **First cPanel / EasyApache 4 channel:** `ea-apache24-mod_pagespeed` RPMs.
- The `+rN` package-revision scheme is established (mapping to the RPM
  `Release` field and the deb revision).

### **1.1.0** (2026-05-15, module) — Security update: general availability, clearing a six-year CVE backlog including CVE-2023-4863.

The first We-Amp release of the maintained line, continuing directly from
the final open-source release, **1.14.36.1** (August 2020). Everything below is
relative to that baseline — in particular, the security and reliability fixes
repair defects that were present in the final open-source release, not
regressions in this line. See
**[What's new in 1.15](https://modpagespeed.com/docs/release-notes/#115-history)** for the narrative version.

**Security**

- All bundled image codecs and network libraries updated across six years of
  upstream security work: libwebp 1.5.0 (includes the fix for
  **CVE-2023-4863**, the widely exploited WebP heap overflow), libjpeg-turbo
  3.1.x, libpng 1.6.58, and a modern TLS stack. The HTTPS fetcher was
  replaced with libcurl at a current release, clearing a 12-CVE backlog in
  the process, and nginx module builds moved to a 1.30.x baseline covering
  the May 2026 nginx CVE cluster.
- Memory-safety fixes and hardening throughout image processing.
- Admin-surface hardening throughout: constant-time token comparison, strict
  validation of cache-purge request parameters, CSRF protection and security
  headers on the admin endpoints, and mutating endpoints
  restricted to the global admin.
- Bounded resource consumption on untrusted input: response-size and
  header-size caps in the fetcher, an HTML parser that stops at its size
  limit instead of accumulating without bound, and graceful error handling
  where malformed input could previously abort the process.
- On IIS, internal HTTPS fetches validate certificates by default.
- Release integrity: all packages are GPG-signed with a published key, and
  the Windows binaries (DLL and MSI) carry timestamped Authenticode
  signatures.
- Development is backed by continuous sanitizer testing (AddressSanitizer,
  ThreadSanitizer, and Application Verifier on Windows).

**Reliability**

- Fixes for long-standing crash and data-race conditions in the asynchronous
  rewrite lifecycle, the proxy fetch path, and cache write-ordering (a
  large-cache outage could previously produce persistent misses).
- Graceful degradation replaces hard process aborts on recoverable
  conditions.
- Many platform-specific stability fixes; see the per-platform notes below.

**Cyclone Cache — the new disk cache**

- The original file-based cache is replaced by **Cyclone Cache**: a
  fixed-size, memory-mapped, scan-resistant cache shared safely across
  processes, with no periodic cleanup passes and a persistent index, so
  restarts start warm.
- Fully configuration-compatible: `FileCachePath` keeps working and now
  locates the Cyclone cache; obsolete tuning options are accepted as
  deprecated no-ops with a warning.
- The rest of the cache stack is unchanged: LRU cache, shared-memory metadata
  cache, Redis, and Memcached all remain.

**Modernization**

- The build moved from GYP to **Bazel**, with the core on modern C++
  (C++20/23) and all dependencies pinned and vendored; the source tarball
  builds fully offline.
- **Prebuilt, signed packages** replace compile-it-yourself: deb and RPM for
  Apache, a prebuilt dynamic module for stock nginx, and an MSI for IIS.
- **arm64/aarch64 support** added on Linux; 32-bit x86 dropped; Apache 2.2
  dropped (2.4+ only); the Google-era stable/beta/unstable channel split
  collapsed into a single `mod-pagespeed` package.

**Apache**

- A single `mod_pagespeed.so` for Apache 2.4+, installed the same way as
  before (`a2enmod pagespeed`, same configuration layout). Bundled TLS
  symbols are hidden from the host process to prevent library clashes.

**nginx**

- ngx_pagespeed is now maintained in-tree and shipped as a **prebuilt dynamic
  module** loadable into stock nginx 1.26/1.27 with `load_module` — no more
  compiling nginx from source.

**IIS — the IISpeed successor**

- A new native IIS module (`pagespeed_iis.dll`) for IIS 10+ replaces IISpeed,
  built on the IISpeed codebase and brought to parity with the Linux
  platforms (streaming HTML rewriting, in-place
  resource optimization, per-site configuration, the shared admin console).
- Existing IISpeed installs migrate in place: the module reads
  `pagespeed.config` and falls back to an existing `iiswebspeed.config`;
  admin pages live at the standard `/pagespeed_admin` paths.
- Ships as a signed MSI with clean upgrade and uninstall support.

**What stayed the same**

- All configuration directives, the full filter set (40+ filters),
  `.pagespeed.` resource URLs, in-place resource optimization, the admin and
  statistics endpoints, `.htaccess` support on Apache, and the
  `X-Mod-Pagespeed` / `X-Page-Speed` response headers. Obsolete Google-era
  options (update channels, distributed rewriting) are accepted as no-ops
  with a warning rather than breaking startup.

### **1.1.0-beta.1** (2026-02-25, module) — First public beta of the maintained module line, on Apache, nginx and IIS.

1.1.0-beta.1 is the first public beta of the maintained module line.

It built the module for three front ends from one source tree: Apache and nginx,
both stable, and IIS, experimental.
