This release includes 15 security fixes for security teams reviewing exposed deployments.
Topics
+7 more
Affected surfaces
ReleasePort's take
Moderate signalReleasePort Layer 1 version 2.9.1 hardens core admin against XML attacks and patches multiple security issues across webmail, IMAP migration, DKIM key generation, DMARC processing, and global parameters.
Why it matters: All components listed have severity 85–90; operators should upgrade immediately to prevent XML injection, CSV formula injection, IDOR, path traversal, secret disclosure, and cross‑tenant data leakage.
Summary
AI summaryBroad release touches admin, deps, webmail, and imap_migration.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Hardening core admin against XML attacks using defusedxml. Hardening core admin against XML attacks using defusedxml. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Security | High |
Prevent CSV formula injection vulnerability. Prevent CSV formula injection vulnerability. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Security | High |
Fix two IDOR issues in calendar component. Fix two IDOR issues in calendar component. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Security | High |
Bound decompression of DMARC aggregate report archives. Bound decompression of DMARC aggregate report archives. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Security | High |
Fix two security issues in webmail component. Fix two security issues in webmail component. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Security | High |
Enforce access control on quarantine write actions in amavis. Enforce access control on quarantine write actions in amavis. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Security | High |
Prevent cross‑tenant disclosure in IMAP migration API. Prevent cross‑tenant disclosure in IMAP migration API. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Security | High |
Prevent secret disclosure via global parameters API. Prevent secret disclosure via global parameters API. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Security | High |
Enforce access control on account domains field in admin UI. Enforce access control on account domains field in admin UI. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Security | High |
Prevent path traversal via domain name during DKIM key generation. Prevent path traversal via domain name during DKIM key generation. Source: llm_adapter@2026-07-14 Confidence: high |
— |
| Security | High |
Prevent rights file injection via calendar name Prevent rights file injection via calendar name Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Security | High |
Prevent code injection via folder filter parameters in IMAP migration Prevent code injection via folder filter parameters in IMAP migration Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Medium |
Add account bulk delete API endpoint in admin Add account bulk delete API endpoint in admin Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Medium |
Allow policy daemon to listen on Unix domain socket and enable systemd socket activation Allow policy daemon to listen on Unix domain socket and enable systemd socket activation Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Medium |
Add doveadm HTTP API support for core, admin, and webmail Add doveadm HTTP API support for core, admin, and webmail Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Dependency | Low |
Bump caldav from 3.2.0 to 3.2.1 Bump caldav from 3.2.0 to 3.2.1 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Dependency | Low |
Bump django from 5.2.14 to 5.2.15 Bump django from 5.2.14 to 5.2.15 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Dependency | Low |
Bump django-reversion from 6.2.0 to 6.3.0 Bump django-reversion from 6.2.0 to 6.3.0 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Dependency | Low |
Bump vite from 8.0.14 to 8.0.16 in frontend Bump vite from 8.0.14 to 8.0.16 in frontend Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Dependency | Low |
Bump form-data from 4.0.5 to 4.0.6 in frontend Bump form-data from 4.0.5 to 4.0.6 in frontend Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Dependency | Low |
Bump fido2 from 2.2.0 to 2.2.1 Bump fido2 from 2.2.0 to 2.2.1 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Medium |
Fix version retrieval when not installed as package Fix version retrieval when not installed as package Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Medium |
Remove Redis dependency for caching during tests Remove Redis dependency for caching during tests Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Medium |
Pin rq<2.10.0 to prevent rqcron scheduler crash Pin rq<2.10.0 to prevent rqcron scheduler crash Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Medium |
Parse real Outlook Autodiscover XML request body Parse real Outlook Autodiscover XML request body Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Avoid re‑validating domain quota when unchanged in admin UI Avoid re‑validating domain quota when unchanged in admin UI Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Refactor | Low |
Improve crypto key management Improve crypto key management Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Refactor | Low |
Improve i18n core handling Improve i18n core handling Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Refactor | Low |
Use queryset delete in accounts bulk_delete implementation Use queryset delete in accounts bulk_delete implementation Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
Full changelog
What's Changed
- Bump caldav from 3.2.0 to 3.2.1 by @dependabot[bot] in https://github.com/modoboa/modoboa/pull/4043
- Updates for file frontend/src/locale/en/app.po in ru by @transifex-integration[bot] in https://github.com/modoboa/modoboa/pull/4044
- Updates for file modoboa/locale/en/LC_MESSAGES/django.po in ru by @transifex-integration[bot] in https://github.com/modoboa/modoboa/pull/4045
- Updates for file frontend/src/locale/en/app.po in ru by @transifex-integration[bot] in https://github.com/modoboa/modoboa/pull/4046
- chore: update metadata and contributing file by @kryskool in https://github.com/modoboa/modoboa/pull/4048
- Bump django from 5.2.14 to 5.2.15 by @dependabot[bot] in https://github.com/modoboa/modoboa/pull/4049
- fix: retrieve version when not installed as package by @kryskool in https://github.com/modoboa/modoboa/pull/4050
- Bump django-reversion from 6.2.0 to 6.3.0 by @dependabot[bot] in https://github.com/modoboa/modoboa/pull/4052
- chore(deps-dev): bump vite from 8.0.14 to 8.0.16 in /frontend by @dependabot[bot] in https://github.com/modoboa/modoboa/pull/4053
- chore(deps): bump form-data from 4.0.5 to 4.0.6 in /frontend by @dependabot[bot] in https://github.com/modoboa/modoboa/pull/4054
- Don’t depend on running Redis for caching when executing tests by @ntninja in https://github.com/modoboa/modoboa/pull/4051
- fix(calendar): Fixed 2 IDOR issues in calendar component by @tonioo in https://github.com/modoboa/modoboa/pull/4056
- fix(dmarc): bound decompression of aggregate report archives by @tonioo in https://github.com/modoboa/modoboa/pull/4058
- fix(webmail): Fixed 2 security issues in webmail component: by @tonioo in https://github.com/modoboa/modoboa/pull/4057
- fix(export): Prevent CSV formula injection. by @tonioo in https://github.com/modoboa/modoboa/pull/4061
- fix(amavis): Enforce access control on quarantine write actions by @tonioo in https://github.com/modoboa/modoboa/pull/4062
- fix(imap_migration): Fix cross-tenant disclosure in migration API by @tonioo in https://github.com/modoboa/modoboa/pull/4063
- fix(parameters): prevent secret disclosure via global parameters API by @tonioo in https://github.com/modoboa/modoboa/pull/4064
- fix(admin): enforce access control on account domains field by @tonioo in https://github.com/modoboa/modoboa/pull/4070
- fix(admin): prevent path traversal via domain name in DKIM key genera… by @tonioo in https://github.com/modoboa/modoboa/pull/4071
- fix(calendars): prevent rights file injection via calendar name by @tonioo in https://github.com/modoboa/modoboa/pull/4072
- fix(imap_migration): prevent code injection via folder filter params by @tonioo in https://github.com/modoboa/modoboa/pull/4073
- chore(deps): bump fido2 from 2.2.0 to 2.2.1 by @dependabot[bot] in https://github.com/modoboa/modoboa/pull/4069
- Better crypto key management by @tonioo in https://github.com/modoboa/modoboa/pull/4080
- fix(core): pin rq<2.10.0 to prevent rqcron scheduler crash by @BrunoNyland in https://github.com/modoboa/modoboa/pull/4076
- fix(autoconfig): parse real Outlook Autodiscover XML request body by @BrunoNyland in https://github.com/modoboa/modoboa/pull/4075
- Fix/i18n core improvements v2 by @BrunoNyland in https://github.com/modoboa/modoboa/pull/4078
- feat(admin): add account bulk delete API endpoint by @tonioo in https://github.com/modoboa/modoboa/pull/4081
- Allow policy daemon to listen on Unix domain socket and systemd socket activation by @ntninja in https://github.com/modoboa/modoboa/pull/3677
- fix(security): hardening core admin by @tonioo in https://github.com/modoboa/modoboa/pull/4079
- feat(core,admin,webmail): add doveadm HTTP API support by @tonioo in https://github.com/modoboa/modoboa/pull/4083
- fix(admin): don't re-validate domain quota when quota is unchanged by @tonioo in https://github.com/modoboa/modoboa/pull/4086
- refactor(admin): use queryset delete in accounts bulk_delete by @tonioo in https://github.com/modoboa/modoboa/pull/4087
- chore(deps): bump django from 5.2.15 to 5.2.16 by @dependabot[bot] in https://github.com/modoboa/modoboa/pull/4089
- fix(autoconfig): Thunderbird Mobile Autoconfig changes by @pionsys-mhs in https://github.com/modoboa/modoboa/pull/4074
- fix(admin): enable ordering by quota_usage on accounts endpoint by @tonioo in https://github.com/modoboa/modoboa/pull/4093
- security: use defusedxml to protect against XML attacks by @AndrianBalanescu in https://github.com/modoboa/modoboa/pull/4094
- fix(webmail): lazy-load contacts models to allow disabling contacts app by @tonioo in https://github.com/modoboa/modoboa/pull/4096
New Contributors
- @BrunoNyland made their first contribution in https://github.com/modoboa/modoboa/pull/4076
- @AndrianBalanescu made their first contribution in https://github.com/modoboa/modoboa/pull/4094
Full Changelog: https://github.com/modoboa/modoboa/compare/2.9.0...2.9.1
Security Fixes
- fix(calendar): Fixed 2 IDOR issues in calendar component
- fix(dmarc): bound decompression of aggregate report archives
- fix(webmail): Fixed 2 security issues in webmail component
- fix(export): Prevent CSV formula injection.
- fix(amavis): Enforce access control on quarantine write actions
- fix(imap_migration): Fix cross-tenant disclosure in migration API
- fix(parameters): prevent secret disclosure via global parameters API
- fix(admin): enforce access control on account domains field
- fix(admin): prevent path traversal via domain name in DKIM key generation
- fix(calendars): prevent rights file injection via calendar name
- fix(imap_migration): prevent code injection via folder filter params
- fix(core): pin rq<2.10.0 to prevent rqcron scheduler crash
- fix(autoconfig): parse real Outlook Autodiscover XML request body
- fix(security): hardening core admin
- security: use defusedxml to protect against XML attacks
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Modoboa
Mail hosting and management platform including a modern and simplified web user interface.
Beta — feedback welcome: [email protected]