Skip to content

stalwart

v0.16.13 Feature

This release adds 1 notable feature for engineering teams evaluating rollout.

Published 14d Communication & Email
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

caldav carddav imap jmap mail pop3
+4 more
rust server smtp webdav

Affected surfaces

auth deps

Summary

AI summary

Added FreeBSD support and fixed OAuth, PostgreSQL, JMAP VacationResponse/Capabilities, DNS CAA management, duration validation, custom logos, Sieve headers, MTA queue processing, and in‑memory store recovery issues.

Changes in this release

Feature Low

Adds FreeBSD support.

Adds FreeBSD support.

Source: llm_adapter@2026-07-13

Confidence: high

Bugfix High

Allows recovery of misconfigured in‑memory store in recovery mode.

Allows recovery of misconfigured in‑memory store in recovery mode.

Source: granite4.1:30b@2026-07-13-audit

Confidence: low

Bugfix Medium

Fixes OAuth resource indicator acceptance for imap, smtp, pop3, sieve.

Fixes OAuth resource indicator acceptance for imap, smtp, pop3, sieve.

Source: llm_adapter@2026-07-13

Confidence: high

Bugfix Medium

Fixes incomplete PostgreSQL channel binding implementation.

Fixes incomplete PostgreSQL channel binding implementation.

Source: llm_adapter@2026-07-13

Confidence: high

Bugfix Medium

Fixes JMAP capabilities to return RFC-3339‑conformant UTCDate literals.

Fixes JMAP capabilities to return RFC-3339‑conformant UTCDate literals.

Source: llm_adapter@2026-07-13

Confidence: high

Bugfix Medium

Fixes Directory to update local groups only when external directory includes a group attribute.

Fixes Directory to update local groups only when external directory includes a group attribute.

Source: llm_adapter@2026-07-13

Confidence: high

Bugfix Medium

Fixes multiple provider issues in DNS Management (see dns-update crate changelog).

Fixes multiple provider issues in DNS Management (see dns-update crate changelog).

Source: llm_adapter@2026-07-13

Confidence: high

Bugfix Medium

Rejects invalid duration values such as `1h30m`.

Rejects invalid duration values such as `1h30m`.

Source: llm_adapter@2026-07-13

Confidence: high

Bugfix Medium

Fixes custom domain logo branding issue.

Fixes custom domain logo branding issue.

Source: llm_adapter@2026-07-13

Confidence: high

Bugfix Medium

Fixes VacationResponse isEnabled reset behavior in JMAP.

Fixes VacationResponse isEnabled reset behavior in JMAP.

Source: llm_adapter@2026-07-13

Confidence: low

Bugfix Medium

Fixes DNS Management CAA management deleting too many third‑party CAA entries.

Fixes DNS Management CAA management deleting too many third‑party CAA entries.

Source: llm_adapter@2026-07-13

Confidence: low

Bugfix Medium

Adds `Received` headers to auto‑generated Sieve messages and detects loops.

Adds `Received` headers to auto‑generated Sieve messages and detects loops.

Source: granite4.1:30b@2026-07-13-audit

Confidence: low

Bugfix Medium

Restores MTA queue processing resume functionality.

Restores MTA queue processing resume functionality.

Source: granite4.1:30b@2026-07-13-audit

Confidence: low

Bugfix Low

Resets `isEnabled` to false in JMAP VacationResponse when properties change.

Resets `isEnabled` to false in JMAP VacationResponse when properties change.

Source: granite4.1:30b@2026-07-13-audit

Confidence: low

Bugfix Low

Corrects CAA management to avoid deleting excess third‑party CAA entries.

Corrects CAA management to avoid deleting excess third‑party CAA entries.

Source: granite4.1:30b@2026-07-13-audit

Confidence: low

Full changelog

[0.16.13] - 2026-07-12

If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.

Added

  • FreeBSD support.

Changed

Fixed

  • OAuth resource indicators: Accept imap, smtp, pop3 and sieve as valid resource indicators for OAuth access tokens.
  • PostgreSQL: Incomplete channel binding implementation.
  • JMAP:
    • VacationResponse: isEnabled reset to false whenever properties are changed.
    • Capabilities: Return RFC-3339-conformant UTCDate literals in capabilities: min 0001-01-01T00:00:00Z, max 9999-12-31T23:59:59Z.
  • Directory: Update local groups only when the external directory includes a group attribute.
  • DNS Management:
    • CAA management deletes too third-party CAA entries.
    • Multiple provider fixes (see dns-update crate changelog).
  • Reject invalid duration values (e.g. 1h30m).
  • Branding: Custom logos for domains do not work.
  • Sieve: add Received headers to auto-generated messages and detect loops.
  • MTA: Resume queue processing does not work.
  • Misconfigured in-memory store cannot be recovered in recovery mode.

Check binary attestation here

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track stalwart

Get notified when new releases ship.

Sign up free

About stalwart

All-in-one Mail & Collaboration server. Secure, scalable and fluent in every protocol (IMAP, JMAP, SMTP, CalDAV, CardDAV, WebDAV).

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]