This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+6 more
ReleasePort's take
Moderate signalThe release adds the X-Forwarded-By header for request tracing.
Why it matters: Security relevance is high (severity 90) for HTTP‑header surfaces; operators should monitor this change when handling forwarded requests.
Summary
AI summarySecurity fix adds X-Forwarded-By header (GHSA-rfhj-4wcq-74xg).
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Adds X-Forwarded-By header for request tracing Adds X-Forwarded-By header for request tracing Source: llm_adapter@2026-07-18 Confidence: high |
— |
Full changelog
Changelog :mailbox:
-
Ensure we set X-Forwarded-By, see GHSA-rfhj-4wcq-74xg
-
This release was triggered by PR/Issue 4070.
-
The release notes of the original main release can be accessed via menu item 'Release notes' on mailu.io.
Update
The main version X.Y (e.g. 1.9) will always reflect the latest version of the branch. To update your Mailu installation simply pull the latest images `docker compose pull && docker compose up -d`.
The pinned version X.Y.Z (e.g. 1.9.1) is not updated. It is pinned to the commit that was used for creating this release. You can use a pinned version to make sure your Mailu installation is not suddenly updated when recreating containers. The pinned version allows the user to manually update. It also allows to go back to a previous pinned version.
Security Fixes
- GHSA-rfhj-4wcq-74xg – Ensure X-Forwarded-By header is set to mitigate abuse
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]