Skip to content

Mailu

v2024.06.56 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

dkim dmarc docker email fetchmail imap
+6 more
letsencrypt mail mailserver pop3 smtp webmail

Affected surfaces

auth

Summary

AI summary

Roundcube upgraded to 1.6.17 fixing CVE-2026-54432 and CVE-2026-54433.

Full changelog

Changelog :mailbox:

  • roundcube 1.6.17 - fix multiple CVEs: CVE-2026-54432 CVE-2026-54433

  • This release was triggered by PR/Issue 4073.

  • The release notes of the original main release can be accessed via menu item 'Release notes' on mailu.io.

Update

The main version X.Y (e.g. 1.9) will always reflect the latest version of the branch. To update your Mailu installation simply pull the latest images `docker compose pull && docker compose up -d`.

The pinned version X.Y.Z (e.g. 1.9.1) is not updated. It is pinned to the commit that was used for creating this release. You can use a pinned version to make sure your Mailu installation is not suddenly updated when recreating containers. The pinned version allows the user to manually update. It also allows to go back to a previous pinned version.

Security Fixes

  • CVE-2026-54432 — fixed in Roundcube 1.6.17
  • CVE-2026-54433 — fixed in Roundcube 1.6.17

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Mailu

Get notified when new releases ship.

Sign up free

About Mailu

Insular email distribution - mail server as Docker images

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]