Skip to content

MailFlow

v2.3.0 Security

This release includes 4 security fixes for security teams reviewing exposed deployments.

Published 19d Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 4 known CVEs

Topics

email emailclient unifiedinbox webmail

Affected surfaces

auth rce_ssrf

Summary

AI summary

Updates New features, Security & reliability hardening, and v2.3.0 across a mixed release.

Full changelog

v2.3.0

New features

  • Custom AI actions — define your own AI actions with a dropdown menu, synced across devices (#202)
  • AI results persist per device — AI action output is saved and restored when you revisit a message (#204)
  • CardDAV contact sync — sync contacts from external servers like Nextcloud (#209)
  • Recipient editing in compose — edit and copy To/Cc/Bcc recipients directly; fixed suggestion-list scrolling (#210)
  • Read/unread rule condition — inbox rules can now match on whether a message is read or unread, useful when running rules over existing mail (#203)

Fixes

  • Login screen now follows your selected theme (and your OS light/dark preference on first visit) instead of always showing dark (#208)
  • SSO: honor require_email_verified = off when provisioning new users (#211)
  • Layout preset is sanitized on read, hardening against removed presets (#207)

Security & reliability hardening

  • SSRF-safe outbound fetch, Redis-backed rate limiting, robust async error handling, and cleaner worker teardown
  • SSO-lockout guard, bulk-move resync, and snippet indexer scheduling
  • End-to-end audit follow-ups: ReDoS guards on inbox-rule regex, IMAP reconnect lock, CardDAV auth hardening, Microsoft OAuth refresh gating/serialization, session + trusted-device invalidation on password reset, fail-safe credential decryption, login/CardDAV timing-oracle fixes, duplicate-account advisory lock, CSRF custom-header defense, and a reconcile-delete race guard
  • Client-side email HTML sanitization (div + print) and DOMPurify 3.4.11

Security Fixes

  • SSRF‑safe outbound fetch, Redis‑backed rate limiting, robust async error handling and cleaner worker teardown
  • SSO lockout guard, bulk‑move resync, snippet indexer scheduling
  • ReDoS guards on inbox‑rule regex, IMAP reconnect lock, CardDAV auth hardening, MS OAuth refresh gating/serialization, session + trusted‑device invalidation on password reset, fail‑safe credential decryption, login/CardDAV timing‑oracle fixes, duplicate‑account advisory lock, CSRF custom‑header defense, reconcile‑delete race guard
  • Client‑side email HTML sanitization using DOMPurify 3.4.11

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track MailFlow

Get notified when new releases ship.

Sign up free

About MailFlow

Unified webmail client

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]