This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+4 more
Affected surfaces
Summary
AI summaryUpdates ACME, Sieve, and https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md across a mixed release.
Full changelog
[0.16.9] - 2026-06-15
If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.
Added
- ACME: Allow specifying a preferred certificate chain.
Changed
Fixed
- JMAP:
*/changesmethods leak ids of non-shared objects (reported by @5ud0er). - Sieve: Do not allow invalid certs in
http_headerfunction. - FoundationDB: Fix read version cache expiration logic.
- MTA: Re-scheduling or editing a queued message reports success but persists nothing for recipients in a non-
defaultvirtual queue. - CardDAV: Version requests included in
address-dataare ignored. - ACME: Add freshness check when renewing certificates.
- Autodiscover v2: Read email address from query parameters.
- Sieve: Do not keep copies of redirected messages when
keepis not specified. - Registry: Object ids are parsed as numbers.
Check binary attestation here
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About stalwart
All-in-one Mail & Collaboration server. Secure, scalable and fluent in every protocol (IMAP, JMAP, SMTP, CalDAV, CardDAV, WebDAV).
Beta — feedback welcome: [email protected]