This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+4 more
Affected surfaces
Summary
AI summaryUpdates https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md, Encryption-at-rest, and S3 across a mixed release.
Full changelog
[0.16.11] - 2026-06-25
If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.
Added
- Encryption-at-rest: Support for
AES-256-GCMandChaCha20-Poly1305for S/MIME (#161). - S3: Support for
allowInvalidCertsoption to allow connecting to S3 endpoints with invalid TLS certificates. - Redis Sentinel support as an in-memory store and cluster coordinator backend (#2430).
Changed
Fixed
- DANE: Verify DNSSEC is supported by the resolver before attempting to validate TLSA records.
- TLS: Update search index when file-backed certificates are refreshed.
- JMAP:
Principal/queryreturns broad results when anameoremailfilter cannot be resolved. - Webhooks: event IDs collide for same event type emitted in the same second.
Check binary attestation here
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About stalwart
All-in-one Mail & Collaboration server. Secure, scalable and fluent in every protocol (IMAP, JMAP, SMTP, CalDAV, CardDAV, WebDAV).
Beta — feedback welcome: [email protected]