v0.15.5

stalwartlabs/stalwartv0.15.5Feb 14, 2026by mdecimus

AI Summary

This patch release fixes a critical CVE vulnerability (CVE-2026-26312) related to OOM crashes when the mail parser encounters cyclical MIME structures, along with several JMAP query and tracing fixes.

Key Highlights

  • Fixed OOM vulnerability (CVE-2026-26312) with cyclical MIME structures
  • Fixed tracing indexing when using separate stores
  • Fixed upToId computation in JMAP */queryChanges
  • Fixed createdIds inclusion in JMAP responses when property is present
  • Fixed query arguments in Email/queryChanges

Full Release Notes

## [0.15.5] - 2026-02-14

If you are upgrading from v0.14.x and below, this version includes **multiple breaking changes**. Please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_15.md) for more information on how to upgrade from previous versions.
If you are upgrading from v0.15.x, replace the binary and update the webadmin.

## Added

## Changed

## Fixed
- IMAP/JMAP: OOM when `mail-parser` returns cyclical MIME structures ([CVE-2026-26312](https://github.com/stalwartlabs/stalwart/security/advisories/GHSA-jm95-876q-c9gw)).
- Tracing: Fix tracing indexing when using separate stores.
- JMAP: Fix `upToId` computation in `*/queryChanges`.
- JMAP: Include createdIds when the property is present.
- JMAP: Respect query arguments in `Email/queryChanges`.
- JMAP: Return the correct container/item change id when there are no changes.

<hr />

### Check binary attestation at [here](https://github.com/stalwartlabs/stalwart/attestations/18954348)