v0.16.9
anomalyco/opentuiv0.16.9Jun 16, 2026by github-actions[bot]
AI Summary
This release focuses on security and bug fixes for the Stalwart Mail Server, addressing issues with JMAP, Sieve, FoundationDB, MTA, and CardDAV, while adding features for ACME certificate management.
Key Highlights
- Fixed JMAP `*/changes` methods leaking ids of non-shared objects
- Added ACME preferred certificate chain specification
- Fixed MTA message re-scheduling/editing persistence issues in non-default queues
- Improved FoundationDB read version cache expiration logic
New Features
- ACME: Allow specifying a preferred certificate chain
- ACME: Add freshness check when renewing certificates
- Autodiscover v2: Read email address from query parameters
- Registry: Object ids are parsed as numbers
Full Release Notes
## [0.16.9] - 2026-06-15 If you are upgrading from v0.16.x, replace the binary (or run `docker pull`). If you are upgrading from v0.15.x and below, please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md) for more information on how to upgrade from previous versions. ## Added - ACME: Allow specifying a preferred certificate chain. ## Changed ## Fixed - JMAP: `*/changes` methods leak ids of non-shared objects (reported by @5ud0er). - Sieve: Do not allow invalid certs in `http_header` function. - FoundationDB: Fix read version cache expiration logic. - MTA: Re-scheduling or editing a queued message reports success but persists nothing for recipients in a non-`default` virtual queue. - CardDAV: Version requests included in `address-data` are ignored. - ACME: Add freshness check when renewing certificates. - Autodiscover v2: Read email address from query parameters. - Sieve: Do not keep copies of redirected messages when `keep` is not specified. - Registry: Object ids are parsed as numbers. <hr /> ### Check binary attestation [here](https://github.com/stalwartlabs/stalwart/attestations/31329451)