New Appliance Release 15.1.0.1

Information notice SEPPmail Appliances Appliance Release Info

Updates

Information

A new SEPPmail Appliance release has been published. Please see the revision history and the extended release notes for further details.

A quick-fix release for 15.1.0 was necessary because of an error in the GINA domain settings page in the Admin GUI.


Hotfix release 15.1.0.1 (Released 2026-09-29)
Admin
  • Fixed internal server error in edit GINA domain page.

Release 15.1.0 (Released 2026-09-28)
Admin
  • Improved monitoring of LDAP database growth to help detect abnormal storage increases before available disk space becomes critical.
  • Improved tenant-specific administration so delegated administrators can access only the accounts associated with their assigned tenant.
  • Added a connection test for external keyserver settings to simplify configuration verification.
Background tasks
  • Added improved administrator notification when an email backup cannot be completed.
  • Added support for notifying communication partners about expiring certificates and facilitating certificate renewal.
  • Extended disk-space monitoring to provide notifications when the LFM storage area approaches its configured capacity limit.
Database
  • Adjusted LDAP synchronization settings to improve operation on medium and large installations.
Libraries
  • Update OpenSSL to version 3.5.8
  • Update OpenSSH sshd to version 10.4
RestAPI
  • Added auditing capabilities for REST API requests to improve traceability of API activity.
  • Corrected an incomplete API definition for cryptographic certificate information.
Rule engine
  • Added message metadata that records actions performed during mail processing, allowing downstream applications to identify how a message was handled.
  • Added PostgreSQL integration capabilities for Rule Engine custom commands, enabling controlled database lookups and updates for supported use cases.
Refactoring
  • Modernized the internal implementation used for certificate revocation checks.
Security
  • Affected versions: ≤15.0.6.1 - CVE-ID: Pending - CVSS Score: 9.9
    Description: Insufficient authorization controls in a cryptographic management API could allow an authenticated user with limited permissions to perform operations beyond their intended scope, potentially affecting system-wide trust configuration.
    Fix Description: Restrict access to the REST endpoint /crypto/rootca to MSP tokens.

  • Affected versions: ≤15.1.0 - CVE-ID: Pending - CVSS Score: 7.1
    Description: Insufficient output sanitization in the log viewer could allow specially crafted message data to execute unintended browser-side content when viewed by an administrator.
    Fix Description: Escape all external data to prevent content execution.

  • Updated internal command execution to use safer command-handling mechanisms.

Webmail
  • Corrected the styling of generated email notifications to ensure a consistent appearance.
  • Added support for restricting file types that external communication partners can upload through GINA.
September 29, 2026 · 09:18 CEST

← Back