This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+4 more
Affected surfaces
Summary
AI summaryUpdates https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md, OAuth, and MTA across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | Low |
DNS updater upgraded to `dns-update-v0.5.1`. DNS updater upgraded to `dns-update-v0.5.1`. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
MTA sub-addressing with external directories now returns `550 Mailbox not found`. MTA sub-addressing with external directories now returns `550 Mailbox not found`. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
Disabled aliases no longer receive messages in MTA. Disabled aliases no longer receive messages in MTA. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
JMAP FileNode/get returns correct non‑stale state string. JMAP FileNode/get returns correct non‑stale state string. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
Rate limiter no longer panics when periods under 1 second are used. Rate limiter no longer panics when periods under 1 second are used. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Medium |
CalDAV/CardDAV writes vanished tombstone for items deleted via JMAP. CalDAV/CardDAV writes vanished tombstone for items deleted via JMAP. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Bugfix | Low |
Made `SieveSystemInterpreter.defaultReturnPath` and `MtaQueueQuota.match` optional expressions. Made `SieveSystemInterpreter.defaultReturnPath` and `MtaQueueQuota.match` optional expressions. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Refactor | Medium |
OAuth access tokens use AES-256-GCM-SIV AEAD format with account name for proxy routing. OAuth access tokens use AES-256-GCM-SIV AEAD format with account name for proxy routing. Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Refactor | Low |
Added more internal TLDs to domain validation checks. Added more internal TLDs to domain validation checks. Source: llm_adapter@2026-06-06 Confidence: high |
— |
Full changelog
[0.16.8] - 2026-06-06
If you are upgrading from v0.16.x, replace the binary (or run docker pull). If you are upgrading from v0.15.x and below, please read the upgrading documentation for more information on how to upgrade from previous versions.
Added
Changed
- OAuth: Rework access tokens to an
AES-256-GCM-SIVAEAD format that carries the account name for proxy routing. - Added more internal TLDs to the domain validation.
Fixed
- MTA:
- Sub-addressing with external directories returns
550 Mailbox not found. - Disabled aliases continue receiving messages.
- Sub-addressing with external directories returns
- JMAP for File Storage:
FileNode/getreturns a stale state string. - Make
SieveSystemInterpreter.defaultReturnPathandMtaQueueQuota.matchoptional expressions. - Rate limiter panics when periods under 1 second are used.
- CalDAV/CardDAV: Calendar events, contacts, calendars and address books deleted via JMAP do not write a vanished tombstone.
- DNS updater: bump to
dns-update-v0.5.1.
Check binary attestation here
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About stalwart
All-in-one Mail & Collaboration server. Secure, scalable and fluent in every protocol (IMAP, JMAP, SMTP, CalDAV, CardDAV, WebDAV).
Beta — feedback welcome: [email protected]