← Back to all sparks
M

mailcow

COMMS
Velocity5.0

Dockerized open-source mail server suite

mailcow's release notes are almost entirely upstream security currency.

mail-serverself-hostedsecurity-updatesdockerupstream-currencyweb-hardening
Current state
mailcow ships named seasonal releases with lettered revisions, and nearly every revision exists to pull in an upstream security fix - Redis, ClamAV, SOGo, Rspamd, nginx, unbound, Postfix. Revision B of the Mooly 2026 release updates Redis 7.4.10, ClamAV 1.4.6, and SOGo 5.12.10, adds minor web UI and nginx hardening, and removes a legacy DeltaChat sieve rule. The last release with genuinely new features was the March cut, which added forced 2FA, ACME DNS-01 challenges, and a passwordless autodiscover endpoint.
Where it's heading
For a self-hosted mail stack that bundles a dozen upstream components, keeping current with their CVEs is the product, and mailcow has organized its release cadence around exactly that. The pattern is consistent: a named release with some feature content every few months, then lettered revisions that are pure security currency plus small web UI escaping and validation fixes. The web interface is where mailcow's own code gets hardened - HTML escaping in quarantine views and sieve editors recurs across several revisions.
Prediction
Expect the next entry to be another lettered revision carrying upstream updates, with the next named release likely bundling whatever feature work has accumulated since March.

Recent moves

  1. 1d ago

    🏖️🐮 Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3 - Revision B

    Redis 7.4.10, ClamAV 1.4.6, and SOGo 5.12.10 pulled in for multiple security issues, plus minor hardening across the web UI and nginx and removal of a legacy DeltaChat auto-filing sieve rule. The second revision of the Mooly release and the fourth consecutive entry driven by upstream security work.

    View source ↗
  2. 19d ago

    🏖️🐮 Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3 - Revision A

    Rspamd 4.1.4, a fix for nginx CVE-2026-42533, and general hardening, alongside real bug fixes - quarantine subject display restored, IPv6 default_server binding gated on ENABLE_IPV6, time-limited aliases no longer silently discarded. Flagged as strongly recommended.

    View source ↗
  3. 1mo ago

    🏖️🐮 Mooly 2026 | Postfix 3.10.12, Rspamd 4.1.0 & Nginx 1.30.3

    The base Mooly release: Rspamd 4.1.0, nginx 1.30.3, SOGo 5.12.9, and Postfix migrated from Debian bookworm to trixie, plus mobileconfig password escaping and a force_tfa template fix. The base-image move is the item with real operational weight.

    View source ↗
  4. 2mo ago

    Third May revision: unbound CVE and nginx 1.30.2

    An unbound CVE fix, nginx 1.30.2, and a run of CI action bumps. Pure currency with nothing touching mailcow's own behavior.

    View source ↗
  5. 3mo ago

    Second May revision: quarantine table HTML escaping

    HTML escaping in the quarantine table, nginx 1.30.1, and Uzbek added as a language. The escaping fix belongs to the recurring web-UI hardening thread rather than the upstream-bump one.

    View source ↗
  6. 3mo ago

    SOGo 5.12.8 covering four upstream security issues

    A single-item revision pulling SOGo 5.12.8 for four security issues, with an upgrade strongly recommended. The clearest example of the pattern: one upstream advisory, one mailcow revision.

    View source ↗