← Back to all sparks
M

mailcow

COMMS
Velocity5.0

Dockerized open-source mail server suite

Six releases, and every one of them is a security update in some form.

mail-serverself-hostedcve-responsexss-hardeningupstream-bundlingtwo-factor-auth
Current state
mailcow ships on a monthly tag with lettered revisions, and this window contains no release that isn't security-driven. The May line ran to three revisions in two weeks — an unnamed fix with a CVE identifier withheld until later, SOGo 5.12.8 covering four upstream issues, an unbound CVE, HTML escaping added to the quarantine table, sieve filter editor and queue manager. July brought Rspamd 4.1.0 and later 4.1.4, nginx 1.30.3 and a CVE fix, Postfix moved off bookworm, and a release described only as hardening.
Where it's heading
Two distinct pressures are visible. One is upstream: mailcow bundles Postfix, Rspamd, SOGo, nginx, unbound and Dovecot, so every one of their advisories becomes a mailcow release, and the base image migration from bookworm to trixie is that same maintenance surfacing at the OS layer. The other is the project's own web UI, where output escaping is being retrofitted view by view — quarantine table, sieve editor, queue manager, quarantine overview — which reads as a systematic pass rather than isolated reports. Earlier releases in the feed show where feature work went when it happened: forced 2FA, ACME DNS-01 challenges, and admin controls over EAS and DAV access.
Prediction
Expect the monthly-plus-revisions rhythm to continue with upstream component bumps driving most of it, and the web UI escaping pass to reach the remaining admin views.

Recent moves

  1. 2d ago

    🏖️🐮 Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3 - Revision A

    A revision release the project urges users to apply immediately: Rspamd to 4.1.4, an nginx CVE closed, a hardening change, and quarantine overview subject display restored. The escaping and hardening work in the web UI continues in the same place it has been landing all window.

    View source ↗
  2. 19d ago

    🏖️🐮 Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3

    The July base release, and the closest thing here to routine platform work: Rspamd 4.1.0, nginx 1.30.3, SOGo 5.12.9, and Postfix migrated off bookworm. Bundling that many upstream components is what makes this feed's cadence a function of other projects' release schedules.

    View source ↗
  3. 2mo ago

    Third May revision: unbound CVE and nginx 1.30.2

    The thinnest release in the window — an unbound CVE fix, an nginx bump, translation updates and a run of bot-authored action version bumps. The third revision of the same monthly tag in two weeks.

    View source ↗
  4. 2mo ago

    Second May revision: quarantine table HTML escaping

    Adds HTML escaping to the quarantine table alongside an nginx bump — the same class of fix that lands in the sieve editor and queue manager in the base May release and the quarantine overview in July. Read together, these are a deliberate sweep over the admin UI's output paths.

    View source ↗
  5. 2mo ago

    SOGo 5.12.8 covering four upstream security issues

    A single-change revision that exists purely to carry SOGo 5.12.8 and the four security issues it addresses. The clearest illustration of mailcow's position downstream of its bundled components — one upstream advisory, one mailcow release.

    View source ↗
  6. 2mo ago

    May base release: undisclosed CVE plus web UI escaping

    Ships a security fix whose CVE identifier was deliberately withheld until later, plus HTML escaping in the sieve filter edit view and queue manager and postscreen access list updates. The start of the May run that needed three further revisions to settle.

    View source ↗