github foxcpp/maddy v0.9.6
[SECURITY] maddy 0.9.6

3 hours ago

Security fixes

  • proxy_protocol: Require explicit trust all to allow any IP to use PROXY.
    This prevents unintended clients from supplying PROXY protocol headers (GHSA-rpmv-mh3g-cf5c).

  • auth/plain_separate: Require either a pass directive or no_pass.
    This prevents misconfigured authentication modules from skipping
    password verification (GHSA-vc2f-9mpf-273q).

  • endpoint/smtp: Correct handling of the TLS-Required header.
    The override is now limited to Submission endpoints and is ignored on regular SMTP/LMTP (GHSA-g8mw-9qf4-cg5x).

  • limits/limiters: Fix an incorrect bucket capacity check that could
    result in deadlock when a lot (20k+) of distinct domains are accumulated in limiter bucket.
    (GHSA-f2p9-pvm4-fhrj).

Fixes

  • table/chain: Preserve all values returned by multi-value tables.
  • target/smtp: Treat downstream DNS errors as temporary failures.
  • limits/limiters: Fix a panic when the bucket set is full.
  • modify/dkim: Do not oversign the Sender header by default.
  • log: Fix logger formatting and duplicate logger names.
  • storage/imapsql: Update go-imap-sql.

Minor changes

  • Go 1.26 is now the minimum supported Go version.
  • Strip the v prefix from version tags when building custom versions.

Don't miss a new maddy release

NewReleases is sending notifications on new releases.