This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+4 more
Affected surfaces
Summary
AI summaryAdded FreeBSD support and fixed OAuth, PostgreSQL, JMAP VacationResponse/Capabilities, DNS CAA management, duration validation, custom logos, Sieve headers, MTA queue processing, and in‑memory store recovery issues.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Adds FreeBSD support. Adds FreeBSD support. Source: llm_adapter@2026-07-13 Confidence: high |
— |
| Bugfix | High |
Allows recovery of misconfigured in‑memory store in recovery mode. Allows recovery of misconfigured in‑memory store in recovery mode. Source: granite4.1:30b@2026-07-13-audit Confidence: low |
— |
| Bugfix | Medium |
Fixes OAuth resource indicator acceptance for imap, smtp, pop3, sieve. Fixes OAuth resource indicator acceptance for imap, smtp, pop3, sieve. Source: llm_adapter@2026-07-13 Confidence: high |
— |
| Bugfix | Medium |
Fixes incomplete PostgreSQL channel binding implementation. Fixes incomplete PostgreSQL channel binding implementation. Source: llm_adapter@2026-07-13 Confidence: high |
— |
| Bugfix | Medium |
Fixes JMAP capabilities to return RFC-3339‑conformant UTCDate literals. Fixes JMAP capabilities to return RFC-3339‑conformant UTCDate literals. Source: llm_adapter@2026-07-13 Confidence: high |
— |
| Bugfix | Medium |
Fixes Directory to update local groups only when external directory includes a group attribute. Fixes Directory to update local groups only when external directory includes a group attribute. Source: llm_adapter@2026-07-13 Confidence: high |
— |
| Bugfix | Medium |
Fixes multiple provider issues in DNS Management (see dns-update crate changelog). Fixes multiple provider issues in DNS Management (see dns-update crate changelog). Source: llm_adapter@2026-07-13 Confidence: high |
— |
| Bugfix | Medium |
Rejects invalid duration values such as `1h30m`. Rejects invalid duration values such as `1h30m`. Source: llm_adapter@2026-07-13 Confidence: high |
— |
| Bugfix | Medium |
Fixes custom domain logo branding issue. Fixes custom domain logo branding issue. Source: llm_adapter@2026-07-13 Confidence: high |
— |
| Bugfix | Medium |
Fixes VacationResponse isEnabled reset behavior in JMAP. Fixes VacationResponse isEnabled reset behavior in JMAP. Source: llm_adapter@2026-07-13 Confidence: low |
— |
| Bugfix | Medium |
Fixes DNS Management CAA management deleting too many third‑party CAA entries. Fixes DNS Management CAA management deleting too many third‑party CAA entries. Source: llm_adapter@2026-07-13 Confidence: low |
— |
| Bugfix | Medium |
Adds `Received` headers to auto‑generated Sieve messages and detects loops. Adds `Received` headers to auto‑generated Sieve messages and detects loops. Source: granite4.1:30b@2026-07-13-audit Confidence: low |
— |
| Bugfix | Medium |
Restores MTA queue processing resume functionality. Restores MTA queue processing resume functionality. Source: granite4.1:30b@2026-07-13-audit Confidence: low |
— |
| Bugfix | Low |
Resets `isEnabled` to false in JMAP VacationResponse when properties change. Resets `isEnabled` to false in JMAP VacationResponse when properties change. Source: granite4.1:30b@2026-07-13-audit Confidence: low |
— |
| Bugfix | Low |
Corrects CAA management to avoid deleting excess third‑party CAA entries. Corrects CAA management to avoid deleting excess third‑party CAA entries. Source: granite4.1:30b@2026-07-13-audit Confidence: low |
— |
Full changelog
[0.16.13] - 2026-07-12
If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.
Added
- FreeBSD support.
Changed
Fixed
- OAuth resource indicators: Accept
imap,smtp,pop3andsieveas valid resource indicators for OAuth access tokens. - PostgreSQL: Incomplete channel binding implementation.
- JMAP:
- VacationResponse:
isEnabledreset to false whenever properties are changed. - Capabilities: Return RFC-3339-conformant UTCDate literals in capabilities: min
0001-01-01T00:00:00Z, max9999-12-31T23:59:59Z.
- VacationResponse:
- Directory: Update local groups only when the external directory includes a group attribute.
- DNS Management:
- CAA management deletes too third-party CAA entries.
- Multiple provider fixes (see
dns-updatecrate changelog).
- Reject invalid duration values (e.g.
1h30m). - Branding: Custom logos for domains do not work.
- Sieve: add
Receivedheaders to auto-generated messages and detect loops. - MTA: Resume queue processing does not work.
- Misconfigured in-memory store cannot be recovered in recovery mode.
Check binary attestation here
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About stalwart
All-in-one Mail & Collaboration server. Secure, scalable and fluent in every protocol (IMAP, JMAP, SMTP, CalDAV, CardDAV, WebDAV).
Beta — feedback welcome: [email protected]