This release includes breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
Affected surfaces
Summary
AI summaryUpdates Bug Fixes, 1.49.0, and ZMS-54 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Require verified 2FA to retrieve user session if enabled. Require verified 2FA to retrieve user session if enabled. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Medium |
Support phrase search for mailboxes via q parameter. Support phrase search for mailboxes via q parameter. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Medium |
Add authenticated endpoint for API access. Add authenticated endpoint for API access. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Feature | Low |
Add strict2fa configuration setting. Add strict2fa configuration setting. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Bugfix | High |
Fix migrations task and improve migrations runner. Fix migrations task and improve migrations runner. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Bugfix | High |
Fix notifications, encrypted message accounting, IMAP UID handling, and plaintext footer removal on encryption. Fix notifications, encrypted message accounting, IMAP UID handling, and plaintext footer removal on encryption. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Bugfix | Medium |
Collapse large non‑contiguous UID sets into ranged queries for performance. Collapse large non‑contiguous UID sets into ranged queries for performance. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Bugfix | Medium |
Duplicate References and In‑Reply‑To onto encrypted envelope for thread visibility. Duplicate References and In‑Reply‑To onto encrypted envelope for thread visibility. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Bugfix | Medium |
Expose isMessageEncrypted/isEncryptedContentType helpers and use them for encryption‑state detection. Expose isMessageEncrypted/isEncryptedContentType helpers and use them for encryption‑state detection. Source: llm_adapter@2026-06-04 Confidence: high |
— |
| Bugfix | Medium |
Improve logging of encrypted messages. Improve logging of encrypted messages. Source: llm_adapter@2026-06-04 Confidence: high |
— |
Full changelog
1.49.0 (2026-06-04)
Features
Bug Fixes
- Collapse large non-contiguous uid sets into ranged queries (#1089) (9450d1b)
- Duplicate References and In-Reply-To onto encrypted envelope for thread visibility (#1087) (8ace1b3)
- Expose isMessageEncrypted/isEncryptedContentType as static helpers and use them for encryption-state detection (#1086) (ac21021)
- Improve encrypted message logging (#1085) (fea6dad)
- update docs (#1081) (a752f74)
- ZMS-35: Add WITHIN capability support (#1073) (0ac2cfa)
- ZMS-54-2: Add strict2fa setting (#1083) (67bbe8e)
- ZMS-54: Require 2fa to be verified (if enabled) to retrieve user session (#1063) (c90bdb7)
- ZMS-64: Add support for phrase search for mailboxes in q param search (#1079) (e40ba06)
- ZMS-66: fix migrations task (#1092) (c4710a5)
- ZMS-66: Migrations runner improvements (#1084) (af6db2c)
- ZMS-68: Fix notifications, fix encrypted message accounting, improve encryption-on-copy IMAP behaviour, fix IMAP UID behaviour in edge cases, fix plaintext footer not being removed on encryption (#1088) (4be3347)
- ZMS-72: Added authenticated endpoint (#1091) (dedf6e6)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]