Skip to content
postal
Communication & Email
A fully featured open source mail delivery platform for incoming & outgoing e-mail
Ruby
·
Latest 3.3.7 · 10h ago
Security brief →
Features
-
Fully featured open‑source mail server
-
Self‑hosted alternative to transactional email services like SendGrid, Mailgun, and Postmark
-
Comprehensive documentation and support resources
Upgrade now
3.3.7
Security relevant
·
RCE / SSRF
Dependencies
SSRF prevention + SQL injection fix
3.3.6
Security relevant
·
Security fixes
- Sandbox rendered email HTML as extra XSS defence
- Escape interpolated values in select options
- Tighten return_to validation
Full changelog
3.3.6 (2026-04-28)
Bug Fixes
- messages: sandbox rendered email HTML as extra XSS defence (cad2aa6)
Miscellaneous Chores
- ignore node modules and yarn.lock (b611d57)
Code Refactoring
- auth: tighten return_to validation (84f4e20)
- helpers: escape interpolated values in select options (9243524)
- tracking: remove unused src image proxy (dca7f90)
3.3.5
Security relevant
·
Security fixes
- Fixed HTML injection vulnerability in delivery details display
Notable features
- Rails 7.1 and Ruby 3.4 support
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
About
Languages
Ruby
·
Haml
·
SCSS
View on GitHub
Homepage
Documentation
Alternative to
SendGrid
Mailgun
Postmark
Search tools, categories, lists, and users
Use ↑↓ to navigate, Enter to open, Esc to close
No results for ""
⌘K to open
↑↓ navigate
⏎ open