Axigen 10.7.1

Sep 15, 2026   •   Axigen Product Updates

Release Notes

SECURITY

  • Fix stored XSS through HTML in message header display names rendered by the conversation view (AXI-7604 • CVE-Pending • LEARN MORE)
  • Fix HTTP header injection via the recover password proxy endpoint (AXI-7393)
  • Update dependencies to fix multiple vulnerabilities (AXI-7489)
  • Update nanoid to fix the loop vulnerability (AXI-7505)
  • Reject oversized and deeply nested JWTs before parsing them on public session and token endpoints (AXI-7558)
  • Purge push notification ids and refresh tokens when an account is deleted (AXI-7563)
  • Reject authorization codes minted before a password change or session invalidation (AXI-7566)
  • Reject persisted webmail sessions created before a password change or session invalidation (AXI-7567)
  • Revoke push notification ids on password change, forced reset and session invalidation (AXI-7570)
  • Delete the account's refresh token families when the account is deleted (AXI-7571)
  • Fix memory leak when routing a request with an unknown backend hash (AXI-7575)
  • Purge webmail sessions and tokens when an account is removed by LDAP deprovisioning (AXI-7577)
  • Rate-limit failed JWKS fetches and serve the last known-good keys while the provider is down (AXI-7580)
  • Normalize the X-Axigen-Session header to 32 characters so session discards actually match (AXI-7584)
  • Record the session invalidation timestamp when 2FA is enabled from WebAdmin or CLI (AXI-7587)
  • Update dependencies to fix multiple vulnerabilities (AXI-7598)
  • Update dependencies to fix multiple vulnerabilities (AXI-7607)

SERVER

  • Fix scenario that allows a reported mailbox size to exceed the maximum mailbox quota (AXI-7378)
  • Fix scenario resulting in slow account deletions (AXI-7407)
  • Avoid temporary denied responses when detecting high rate of abnormal storage operations (AXI-7442)
  • Fix account creation being treated as a password change for token epoch validation (AXI-7481)
  • Add CLI command to show recent password change timestamps (AXI-7482)
  • Kill the whole bdamserver process group before spawning a replacement master (AXI-7483)
  • Automatically enable APNs, FCM, and per-domain push notification generation when the Mobile Apps license is uploaded (AXI-7507)
  • Return cluster-consistent service information on WebMail Proxy instances (AXI-7508)
  • Serialize webmail session recreation so a losing caller cannot delete the published database row (AXI-7512)
  • Add exception handling for quota, throttling, and permissions checks during UNDO BATCH operations (AXI-7521)
  • Analyze flagging incomplete cluster statistics collection (AXI-7527)
  • Fix SNI for matching a server side certificate when Axigen is acting as client (AXI-7551)
  • Fix use-after-free when reporting blocking transaction details for temporary storage failures (AXI-7582)
  • Fix unexpected memory consumption in specific FTP related scenario (AXI-7600)
  • Fix testMboxStorageAddLoop UnitTest issue: rate-limit from phase 2 tripped by messages from phase 1 (AXI-7596)
  • Fix my_timegm deadlock on TSAN test builds (AXI-7602)

WEBMAIL

  • Fix raw HTML tags appearing in the event description created from a mail (AXI-7395)
  • Resolve the correct message when a draft is opened for editing from a temporary search folder (AXI-7450)
  • Report WebMail and Mobile WebMail usage based on the client type (AXI-7525)
  • Report Mobile Apps usage split by iOS and Android, and custom API client usage (AXI-7526)
  • Fix Calendar current-time indicator swallowing clicks on the grid cell it crosses (AXI-7603)

OTHER

  • Derive the DEB shared-library dependencies from the binaries instead of hardcoding them (AXI-7485)
  • Axigen (ai) Insight (v1.9.6) (AXI-7614)
    • Update the Go toolchain and dependencies to fix multiple vulnerabilities, including a remote denial of service reachable from inbound email (AXI-7609)
    • Bound reverse DNS lookups with a timeout so an unresponsive resolver no longer stalls message processing (AXI-7609)
    • Fix a literal `` client identifier being written into the version header for local and Unix socket connections (AXI-7609)
    • Update the bundled milter, metrics, logging, and networking libraries; exposed metrics and dashboards are unchanged (AXI-7609)
  • Fix DEB packages being generated in an archive format that dpkg and installpkg cannot unpack (AXI-7619)
  • AxiMobile 1.6.0
    • Conversation view page update checker refactor (AM-747)
    • Fix loop auto mark as read conversation (AM-753)
    • Fix offline message not reappearing while the connection is still down (AM-756)
    • Prevent a stale list reload from overwriting a fresher one (AM-760)
    • Fix non-sticky toast not dismissed by subsequent user actions (AM-754)
    • Fix unreliable loading of account security methods during 2FA setup and login (AM-762)
    • Recover from unexpected errors instead of blanking the app (AM-696)
    • Fix loop auto mark as read conversation (AM-753)
    • Fix non-sticky toast not dismissed by subsequent user actions (AM-754)
    • Fix offline message not reappearing while the connection is still down (AM-756)
    • Prevent a stale list reload from overwriting a fresher one (AM-760)
    • Fix unreliable loading of account security methods during 2FA setup and login (AM-762)
    • Fix blank screen when opening notification conversation outside the currently listed folder (AM-768)
    • Fix conversation / mail view state cleared when reopened from another folder via push notification (AM-771)
    • Fix clean-up font-face css rules from mail body (AM-773)
    • Fix missing Sounds option for notifications on iOS (AM-777)
    • Fix silent notifications while the app is open on iOS (AM-778)
    • Fix incorrect server URL used for API requests right after login (AM-782)
    • Add CAPTCHA support to the login page (AM-784)
    • Fix save conversation label changes made via the UI to the on-device cache (AM-785)
    • Prevent duplicate list reload when switching between folders with different conversation-view modes (AM-787)
    • Fix an intermittent app-start race that could leave the mail list stuck loading (AM-788)
    • Raise the API response timeout to tolerate slower servers (AM-791)
    • Fix session expiring repeatedly after renewal via refresh token (AM-792)
    • Upgrade to React 19 (AM-410)
    • Replace Singleton pattern with static helpers/classes in service layer (AM-452)
    • Refactor common page boilerplate into reusable layout components (AM-453)
    • Remove trustAxiMilterLLM backward compatibility fallback from AxiMobile (AM-479)
    • Recognize URLs and email addresses as links while typing and on paste (AM-738)
    • Prevent duplicate syncs, re-renders, and body fetches triggered by draft auto-save (AM-741)
    • Control the conversation view page body loading process (AM-751)
    • Fix pinned dependency versions to allow npm audit fix to apply patch updates (AM-774)
    • Add, edit and remove links in the composer (AM-781)
    • Send the device platform with every API request (AM-786)
    • Translate toast messages at render time instead of dispatch time (AM-797)
    • Add an account resync option that rebuilds the on-device cache (AM-799)
    • Align confirmation dialog buttons with platform conventions (AM-800)
    • Fix push notifications not opening the conversation view when the conversation id is missing (AM-801)
    • Set focus on input when new label / new folder pages are opened (AM-803)
    • Update npm audit-flagged dependencies in webmailapp (AM-805)
    • Remove the link hover effect from the email body styling (AM-806)
    • Fix mail body link and separator colors being inverted twice in dark mode (AM-807)
    • Discard in-flight avatar loads when stopping the avatar service (AM-808)
    • Improve contacts sync logging (AM-810)
    • Keep content visible behind the on-screen keyboard on iOS (AM-812)
    • Keep the keyboard open when showing or hiding the formatting toolbar (AM-813)
    • Restore the vertical spacing on the 2-Step Verification method setup screens (AM-814)

How to Install

To update to this version on Linux, please follow the step by step instructions below:

  1. Download the corresponding install kit for your operating system (see above)

  2. Stop the Axigen service

    Use the command ps aux | grep axigen to confirm that the service is stopped.

  3. Create a backup of the Axigen working directory

    Use the suggestions in our related knowledge base article on how to back up Axigen

    Note: For the restoring process, please consult our article on how to restore an Axigen working directory backup


  4. Run the installer

    Follow the on-screen installer instructions to complete the upgrade process.

    Note: Since this is only an update, please make sure that you skip the Axigen post-install configuration wizard.


  5. Start the Axigen service

    Use the commands: ps aux | grep axigen and /opt/axigen/bin/axigen --version to confirm that the new version is in place.

How to Install

To update to this version on Windows, please follow the step by step instructions below:

  1. Download the corresponding install kit for your operating system (see above)

  2. Stop the Axigen service

  3. Create a backup of the Axigen working directory

    Use the suggestions in our related knowledge base article on how to back up Axigen

    Note: For the restoring process, please consult our article on how to restore an Axigen working directory backup


  4. Run the installer

    Follow the on-screen installer instructions to complete the upgrade process.

    Note: Since this is only an update, please make sure that you skip the Axigen post-install configuration wizard.


  5. Start the Axigen service