Release Notes
SECURITY
- Fix stored XSS through HTML in message header display names rendered by the conversation view (AXI-7604 • CVE-Pending • LEARN MORE)
- Fix HTTP header injection via the recover password proxy endpoint (AXI-7393)
- Update dependencies to fix multiple vulnerabilities (AXI-7489)
- Update nanoid to fix the loop vulnerability (AXI-7505)
- Reject oversized and deeply nested JWTs before parsing them on public session and token endpoints (AXI-7558)
- Purge push notification ids and refresh tokens when an account is deleted (AXI-7563)
- Reject authorization codes minted before a password change or session invalidation (AXI-7566)
- Reject persisted webmail sessions created before a password change or session invalidation (AXI-7567)
- Revoke push notification ids on password change, forced reset and session invalidation (AXI-7570)
- Delete the account's refresh token families when the account is deleted (AXI-7571)
- Fix memory leak when routing a request with an unknown backend hash (AXI-7575)
- Purge webmail sessions and tokens when an account is removed by LDAP deprovisioning (AXI-7577)
- Rate-limit failed JWKS fetches and serve the last known-good keys while the provider is down (AXI-7580)
- Normalize the X-Axigen-Session header to 32 characters so session discards actually match (AXI-7584)
- Record the session invalidation timestamp when 2FA is enabled from WebAdmin or CLI (AXI-7587)
- Update dependencies to fix multiple vulnerabilities (AXI-7598)
- Update dependencies to fix multiple vulnerabilities (AXI-7607)
SERVER
- Fix scenario that allows a reported mailbox size to exceed the maximum mailbox quota (AXI-7378)
- Fix scenario resulting in slow account deletions (AXI-7407)
- Avoid temporary denied responses when detecting high rate of abnormal storage operations (AXI-7442)
- Fix account creation being treated as a password change for token epoch validation (AXI-7481)
- Add CLI command to show recent password change timestamps (AXI-7482)
- Kill the whole bdamserver process group before spawning a replacement master (AXI-7483)
- Automatically enable APNs, FCM, and per-domain push notification generation when the Mobile Apps license is uploaded (AXI-7507)
- Return cluster-consistent service information on WebMail Proxy instances (AXI-7508)
- Serialize webmail session recreation so a losing caller cannot delete the published database row (AXI-7512)
- Add exception handling for quota, throttling, and permissions checks during UNDO BATCH operations (AXI-7521)
- Analyze flagging incomplete cluster statistics collection (AXI-7527)
- Fix SNI for matching a server side certificate when Axigen is acting as client (AXI-7551)
- Fix use-after-free when reporting blocking transaction details for temporary storage failures (AXI-7582)
- Fix unexpected memory consumption in specific FTP related scenario (AXI-7600)
- Fix testMboxStorageAddLoop UnitTest issue: rate-limit from phase 2 tripped by messages from phase 1 (AXI-7596)
- Fix my_timegm deadlock on TSAN test builds (AXI-7602)
WEBMAIL
- Fix raw HTML tags appearing in the event description created from a mail (AXI-7395)
- Resolve the correct message when a draft is opened for editing from a temporary search folder (AXI-7450)
- Report WebMail and Mobile WebMail usage based on the client type (AXI-7525)
- Report Mobile Apps usage split by iOS and Android, and custom API client usage (AXI-7526)
- Fix Calendar current-time indicator swallowing clicks on the grid cell it crosses (AXI-7603)
OTHER
- Derive the DEB shared-library dependencies from the binaries instead of hardcoding them (AXI-7485)
- Axigen (ai) Insight (v1.9.6) (AXI-7614)
- Update the Go toolchain and dependencies to fix multiple vulnerabilities, including a remote denial of service reachable from inbound email (AXI-7609)
- Bound reverse DNS lookups with a timeout so an unresponsive resolver no longer stalls message processing (AXI-7609)
- Fix a literal `
` client identifier being written into the version header for local and Unix socket connections (AXI-7609) - Update the bundled milter, metrics, logging, and networking libraries; exposed metrics and dashboards are unchanged (AXI-7609)
- Fix DEB packages being generated in an archive format that dpkg and installpkg cannot unpack (AXI-7619)
- AxiMobile 1.6.0
- Conversation view page update checker refactor (AM-747)
- Fix loop auto mark as read conversation (AM-753)
- Fix offline message not reappearing while the connection is still down (AM-756)
- Prevent a stale list reload from overwriting a fresher one (AM-760)
- Fix non-sticky toast not dismissed by subsequent user actions (AM-754)
- Fix unreliable loading of account security methods during 2FA setup and login (AM-762)
- Recover from unexpected errors instead of blanking the app (AM-696)
- Fix loop auto mark as read conversation (AM-753)
- Fix non-sticky toast not dismissed by subsequent user actions (AM-754)
- Fix offline message not reappearing while the connection is still down (AM-756)
- Prevent a stale list reload from overwriting a fresher one (AM-760)
- Fix unreliable loading of account security methods during 2FA setup and login (AM-762)
- Fix blank screen when opening notification conversation outside the currently listed folder (AM-768)
- Fix conversation / mail view state cleared when reopened from another folder via push notification (AM-771)
- Fix clean-up font-face css rules from mail body (AM-773)
- Fix missing Sounds option for notifications on iOS (AM-777)
- Fix silent notifications while the app is open on iOS (AM-778)
- Fix incorrect server URL used for API requests right after login (AM-782)
- Add CAPTCHA support to the login page (AM-784)
- Fix save conversation label changes made via the UI to the on-device cache (AM-785)
- Prevent duplicate list reload when switching between folders with different conversation-view modes (AM-787)
- Fix an intermittent app-start race that could leave the mail list stuck loading (AM-788)
- Raise the API response timeout to tolerate slower servers (AM-791)
- Fix session expiring repeatedly after renewal via refresh token (AM-792)
- Upgrade to React 19 (AM-410)
- Replace Singleton pattern with static helpers/classes in service layer (AM-452)
- Refactor common page boilerplate into reusable layout components (AM-453)
- Remove trustAxiMilterLLM backward compatibility fallback from AxiMobile (AM-479)
- Recognize URLs and email addresses as links while typing and on paste (AM-738)
- Prevent duplicate syncs, re-renders, and body fetches triggered by draft auto-save (AM-741)
- Control the conversation view page body loading process (AM-751)
- Fix pinned dependency versions to allow npm audit fix to apply patch updates (AM-774)
- Add, edit and remove links in the composer (AM-781)
- Send the device platform with every API request (AM-786)
- Translate toast messages at render time instead of dispatch time (AM-797)
- Add an account resync option that rebuilds the on-device cache (AM-799)
- Align confirmation dialog buttons with platform conventions (AM-800)
- Fix push notifications not opening the conversation view when the conversation id is missing (AM-801)
- Set focus on input when new label / new folder pages are opened (AM-803)
- Update npm audit-flagged dependencies in webmailapp (AM-805)
- Remove the link hover effect from the email body styling (AM-806)
- Fix mail body link and separator colors being inverted twice in dark mode (AM-807)
- Discard in-flight avatar loads when stopping the avatar service (AM-808)
- Improve contacts sync logging (AM-810)
- Keep content visible behind the on-screen keyboard on iOS (AM-812)
- Keep the keyboard open when showing or hiding the formatting toolbar (AM-813)
- Restore the vertical spacing on the 2-Step Verification method setup screens (AM-814)
Download
How to Install
To update to this version on Linux, please follow the step by step instructions below:
-
Download the corresponding install kit for your operating system (see above)
-
Stop the Axigen service
Use the command ps aux | grep axigen to confirm that the service is stopped.
-
Create a backup of the Axigen working directory
Use the suggestions in our related knowledge base article on how to back up Axigen
Note: For the restoring process, please consult our article on how to restore an Axigen working directory backup
-
Run the installer
Follow the on-screen installer instructions to complete the upgrade process.
Note: Since this is only an update, please make sure that you skip the Axigen post-install configuration wizard.
-
Start the Axigen service
Use the commands: ps aux | grep axigen and /opt/axigen/bin/axigen --version to confirm that the new version is in place.
Download
How to Install
To update to this version on Windows, please follow the step by step instructions below:
-
Download the corresponding install kit for your operating system (see above)
-
Stop the Axigen service
-
Create a backup of the Axigen working directory
Use the suggestions in our related knowledge base article on how to back up Axigen
Note: For the restoring process, please consult our article on how to restore an Axigen working directory backup
-
Run the installer
Follow the on-screen installer instructions to complete the upgrade process.
Note: Since this is only an update, please make sure that you skip the Axigen post-install configuration wizard.
-
Start the Axigen service