Skip to content

๐Ÿ–๏ธ๐Ÿฎ Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3 - Revision A

Latest

Choose a tag to compare

@FreddleSpl0it FreddleSpl0it released this 30 Jul 09:26
489db90

What's Changed

Important

This update addresses several security-related issues in mailcow. We strongly recommend updating your mailcow instance as soon as possible.

Updates and Security

Fixes

  • fix: restore subject display in quarantine overview by @oidipos in #7367
  • [Nginx] only bind IPv6 default_server when ENABLE_IPV6 is set by @smpaz7467 in #7343
  • [Web] fix add/time_limited_alias silently discarding requests and validity by @smpaz7467 in #7345
  • [Web] return sender_acl in get/mailbox API by @smpaz7467 in #7348
  • fix: cors allowed origins settings validation by @fallmo in #7333
  • [Web] harden CORS origin matching and add Vary: Origin by @FreddleSpl0it in #7385
  • [Web] Move mailcow update check to server side by @FreddleSpl0it in #7388
  • [Web] Create default mailbox template with eas and dav access by @FreddleSpl0it in #7389
  • [ACME] Skip mta-sts certificate request when MTA-STS is not active for a domain by @FreddleSpl0it in #7390

New Contributors

Full Changelog: 2026-07...2026-07a