Releases: mailcow/mailcow-dockerized
Release list
๐๏ธ๐ฎ Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3 - Revision B
This release updates Redis, SOGo and ClamAV, addressing multiple security issues.
What's Changed
- [Redis] Update to 7.4.10 by @FreddleSpl0it in #7425
- [Clamd] Update to 1.4.6 by @FreddleSpl0it in #7415
- [SOGo] Update to 5.12.10 by @FreddleSpl0it in #7422
- [Web] Minor hardening across web UI and nginx by @FreddleSpl0it in #7426
- [Dovecot] Remove legacy DeltaChat auto-filing sieve rule by @FreddleSpl0it in #7423
- [Postfix] update postscreen_access.cidr by @milkmaker in #7394
- update README.md sponsors by @MaximalBenedikt in #7392
- update README.md sponsors by @MaximalBenedikt in #7393
- Translations update from Weblate by @milkmaker in #7400
New Contributors
- @MaximalBenedikt made their first contribution in #7392
Full Changelog: 2026-07a...2026-07b
๐๏ธ๐ฎ Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3 - Revision A
What's Changed
Important
This update addresses several security-related issues in mailcow. We strongly recommend updating your mailcow instance as soon as possible.
Updates and Security
- [Rspamd] update to 4.1.4 by @FreddleSpl0it in #7386
- Fix nginx CVE-2026-42533 by @SYNLINQ in #7358
- Update actions/stale action to v11 by @renovate[bot] in #7375
- Hardening mailcow by @FreddleSpl0it in #7387
Fixes
- fix: restore subject display in quarantine overview by @oidipos in #7367
- [Nginx] only bind IPv6 default_server when ENABLE_IPV6 is set by @smpaz7467 in #7343
- [Web] fix add/time_limited_alias silently discarding requests and validity by @smpaz7467 in #7345
- [Web] return sender_acl in get/mailbox API by @smpaz7467 in #7348
- fix: cors allowed origins settings validation by @fallmo in #7333
- [Web] harden CORS origin matching and add Vary: Origin by @FreddleSpl0it in #7385
- [Web] Move mailcow update check to server side by @FreddleSpl0it in #7388
- [Web] Create default mailbox template with eas and dav access by @FreddleSpl0it in #7389
- [ACME] Skip mta-sts certificate request when MTA-STS is not active for a domain by @FreddleSpl0it in #7390
New Contributors
- @oidipos made their first contribution in #7367
- @smpaz7467 made their first contribution in #7343
- @fallmo made their first contribution in #7333
Full Changelog: 2026-07...2026-07a
๐๏ธ๐ฎ Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3
What's Changed
- Update RSPAMD version to 4.1.0 in Dockerfile by @dragoangel in #7172
- [Rspamd] Migrate metadata_exporter to multipart formatter by @FreddleSpl0it in #7283
- Refresh SOGo view after mailbox activation by @ibobgunardi in #7277
- Fix force_tfa not available in mailbox template #7216 by @Snafu in #7275
- [SOGo] Update to 5.12.9 by @goodygh in #7267
- Escape generated password in mobileconfig by @mkuron in #7212
- [Nignx] Update to 1.30.3 by @FreddleSpl0it in #7305
- postfix: migrate from bookworm to trixie by @DerLinkman in #7323
- Update dependency composer/composer to v2.10.2 by @renovate[bot] in #7312
- Update devops-infra/action-pull-request action to v1.2.1 by @renovate[bot] in #7258
- Update actions/stale action to v10.4.0 by @renovate[bot] in #7322
- Update devops-infra/action-pull-request action to v1.4.0 by @renovate[bot] in #7321
- Update dependency php/pecl-mail-mailparse to v3.2.0 by @renovate[bot] in #7189
- Update dependency composer/composer to v2.10.1 by @renovate[bot] in #7193
- Update alpine Docker tag to v3.24 by @renovate[bot] in #7280
- Update actions/checkout action to v7 by @renovate[bot] in #7300
- Update devops-infra/action-pull-request action to v1.3.0 by @renovate[bot] in #7272
- [Postfix] update postscreen_access.cidr by @milkmaker in #7269
- [Postfix] update postscreen_access.cidr by @milkmaker in #7311
- Translations update from Weblate by @milkmaker in #7262
- Translations update from Weblate by @milkmaker in #7263
- Translations update from Weblate by @milkmaker in #7302
- ui, fail2ban fix german ban_list_info translation by @goodygh in #7265
- Refined wording for displaying of active settings on quarantine page. by @ralfbergs in #7326
New Contributors
- @ibobgunardi made their first contribution in #7277
- @Snafu made their first contribution in #7275
- @ralfbergs made their first contribution in #7326
Full Changelog: 2026-05c...2026-07
๐๐ฎ Mooay 2026 | Just another security update - Revision C
What's Changed
- [Nginx] Update to 1.30.2 by @FreddleSpl0it in #7259
- fix unbound CVE-2026-33278 by @SYNLINQ in #7252
- Update actions/stale action to v10.3.0 by @renovate[bot] in #7242
- Translations update from Weblate by @milkmaker in #7245
- Update devops-infra/action-pull-request action to v1.1.2 by @renovate[bot] in #7247
- Update devops-infra/action-pull-request action to v1.1.3 by @renovate[bot] in #7253
- Update devops-infra/action-pull-request action to v1.2.0 by @renovate[bot] in #7254
New Contributors
Full Changelog: 2026-05b...2026-05c
๐๐ฎ Mooay 2026 | Just another security update - Revision B
What's Changed
- [Nginx] Update to 1.30.1 by @FreddleSpl0it in #7240
- escape HTML in quarantine table by @FreddleSpl0it in #7241
- Translations update from Weblate by @milkmaker in #7228
- Add Uzbek language by @Jahongir-Qurbonov in #7224
- Update devops-infra/action-pull-request action to v1.1.1 by @renovate[bot] in #7234
New Contributors
- @Jahongir-Qurbonov made their first contribution in #7224
Full Changelog: 2026-05a...2026-05b
๐๐ฎ Mooay 2026 | Just another security update - Revision A
What's Changed
This release updates SOGo to version 5.12.8, addressing 4 security issues:
https://www.sogo.nu/news/2026/sogo-v5128-released.html
We strongly recommend updating to this version.
- [SOGo] Update to 5.12.8 by @FreddleSpl0it in #7226
Full Changelog: 2026-05...2026-05a
๐๐ฎ Mooay 2026 | Just another security update
What's Changed
This is a small but important update that fixes a security-related issue.
We strongly recommend updating to this version.
The associated CVE identifier will be published at a later time.
- [Postfix] update postscreen_access.cidr by @milkmaker in #7177
- [Postfix] update postscreen_access.cidr by @milkmaker in #7209
- Translations update from Weblate by @milkmaker in #7190
- Translations update from Weblate by @milkmaker in #7218
- [Web] escape HTML in sieve filter edit view and queue manager by @FreddleSpl0it in #7220
Full Changelog: 2026-03b...2026-05
๐๐ฎ Moorch 2026 | forced 2FA, DNS-01, SOGo & Rspamd Updates - Revision B
What's Changed
This is a small but important update that fixes several security-related issues.
We recommend updating to this version.
Associated CVE identifiers will be published later.
- [Web][Dovecot] Improve input validation and escaping by @FreddleSpl0it in #7173
Full Changelog: 2026-03a...2026-03b
๐๐ฎ Moorch 2026 | forced 2FA, DNS-01, SOGo & Rspamd Updates - Revision A
What's Changed
This is a small update that fixes issues related to LDAP and Keycloak authentication, as well as problems with the new ACME DNS-01 challenge feature.
Full release: https://github.com/mailcow/mailcow-dockerized/releases/tag/2026-03
- [Web] Fix LDAP/Keycloak login TypeError - missing JSON decode for attributes by @FreddleSpl0it in #7123
- [ACME] Fix wildcard certificate conflict with MAILCOW_HOSTNAME by @FreddleSpl0it in #7124
- Fix theme localStorage collision with rspamd UI by @rezzorix in #7121
- Translations update from Weblate by @milkmaker in #7130
- [ACME] Skip autodiscover/mta-sts subdomains covered by wildcard certificates by @FreddleSpl0it in #7134
New Contributors
Full Changelog: 2026-03...2026-03a
๐๐ฎ Moorch 2026 | forced 2FA, DNS-01, SOGo & Rspamd Updates
What's Changed
New Features
- [Web] Add forced 2FA setup and password update enforcement by @FreddleSpl0it in #7077
- Add skip feature to mailcow admin password reset script by @HichemAK in #7078
- feat: Implement passwordless autodiscover endpoint by @DerLinkman in #6976
- acme: add DNS challenges by @cjlapao in #6912 (Documentation)
- [SOGo] Build SOGo from source with security patches by @FreddleSpl0it in #7086
- [SOGo] Update to 5.12.5 by @FreddleSpl0it in #7098
- [Rspamd] Update to 3.14.3-1 by @FreddleSpl0it in #7100
Bug Fixes
- Fix lua script sub-addressing by @DocFraggle in #7037
- Document qitem endpoint in openapi.yaml for editing quarantine mails by @jonprocter in #7047
- check_dns: better time measurement by @maxi322 in #6695
- fix: show stopped and failed containers in dashboard and API by @JeremieCrinon in #7082
- Bump alpine version of netfilter by @jovobe in #7060
- [Web] Add missing EAS and DAV protocol options to mailbox bulk actions by @FreddleSpl0it in #7088
- [Web] switch from GET to POST for datatable requests by @FreddleSpl0it in #7089
- [SOGo][Web] use incremental updates for mailbox/alias/resource sync in sogo_static_view by @FreddleSpl0it in #7093
Other
- Translations update from Weblate by @milkmaker in #7040
- Translations update from Weblate by @milkmaker in #7055
- Translations update from Weblate by @milkmaker in #7069
- Translations update from Weblate by @milkmaker in #7091
- Translations update from Weblate by @milkmaker in #7095
- [Postfix] update postscreen_access.cidr by @milkmaker in #7042
- [Postfix] update postscreen_access.cidr by @milkmaker in #7084
- Update actions/stale action to v10.2.0 by @renovate[bot] in #7062
- Update docker/build-push-action action to v7 by @renovate[bot] in #7097
- chore(deps): update dependency composer/composer to v2.9.5 by @renovate[bot] in #6457
- chore(deps): update docker/setup-qemu-action action to v4 by @renovate[bot] in #7092
- chore(deps): update docker/login-action action to v4 by @renovate[bot] in #7094
- chore(deps): update docker/setup-buildx-action action to v4 by @renovate[bot] in #7096
Notes
Special thanks to Philipps-Universitรคt Marburg for sponsoring the development of the forced 2FA setup feature in this release and supporting the continued security improvements of mailcow.
New Contributors
- @HichemAK made their first contribution in #7078
- @jonprocter made their first contribution in #7047
- @JeremieCrinon made their first contribution in #7082
- @jovobe made their first contribution in #7060
- @cjlapao made their first contribution in #6912
Full Changelog: 2026-01...2026-03