Security fixes
-
proxy_protocol: Require explicit
trust allto allow any IP to use PROXY.
This prevents unintended clients from supplying PROXY protocol headers (GHSA-rpmv-mh3g-cf5c). -
auth/plain_separate: Require either a
passdirective orno_pass.
This prevents misconfigured authentication modules from skipping
password verification (GHSA-vc2f-9mpf-273q). -
endpoint/smtp: Correct handling of the
TLS-Requiredheader.
The override is now limited to Submission endpoints and is ignored on regular SMTP/LMTP (GHSA-g8mw-9qf4-cg5x). -
limits/limiters: Fix an incorrect bucket capacity check that could
result in deadlock when a lot (20k+) of distinct domains are accumulated in limiter bucket.
(GHSA-f2p9-pvm4-fhrj).
Fixes
- table/chain: Preserve all values returned by multi-value tables.
- target/smtp: Treat downstream DNS errors as temporary failures.
- limits/limiters: Fix a panic when the bucket set is full.
- modify/dkim: Do not oversign the
Senderheader by default. - log: Fix logger formatting and duplicate logger names.
- storage/imapsql: Update go-imap-sql.
Minor changes
- Go 1.26 is now the minimum supported Go version.
- Strip the
vprefix from version tags when building custom versions.