v0.15.5
stalwartlabs/stalwartv0.15.5Feb 14, 2026by mdecimus
AI Summary
This patch release fixes a critical CVE vulnerability (CVE-2026-26312) related to OOM crashes when the mail parser encounters cyclical MIME structures, along with several JMAP query and tracing fixes.
Key Highlights
- Fixed OOM vulnerability (CVE-2026-26312) with cyclical MIME structures
- Fixed tracing indexing when using separate stores
- Fixed upToId computation in JMAP */queryChanges
- Fixed createdIds inclusion in JMAP responses when property is present
- Fixed query arguments in Email/queryChanges
Full Release Notes
## [0.15.5] - 2026-02-14 If you are upgrading from v0.14.x and below, this version includes **multiple breaking changes**. Please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_15.md) for more information on how to upgrade from previous versions. If you are upgrading from v0.15.x, replace the binary and update the webadmin. ## Added ## Changed ## Fixed - IMAP/JMAP: OOM when `mail-parser` returns cyclical MIME structures ([CVE-2026-26312](https://github.com/stalwartlabs/stalwart/security/advisories/GHSA-jm95-876q-c9gw)). - Tracing: Fix tracing indexing when using separate stores. - JMAP: Fix `upToId` computation in `*/queryChanges`. - JMAP: Include createdIds when the property is present. - JMAP: Respect query arguments in `Email/queryChanges`. - JMAP: Return the correct container/item change id when there are no changes. <hr /> ### Check binary attestation at [here](https://github.com/stalwartlabs/stalwart/attestations/18954348)