App Suite Releases
  • 8.47
  • 8.35
  • 7.10.6
Imprint
  • 8.47
  • 8.35
  • 7.10.6
Imprint
  • Release 8.52Upcoming
  • Release 8.51
  • Release 8.50
    • Noteworthy Changes
      • Important Changes
      • App Suite Middleware
    • Changelogs
      • App Suite UI
      • App Suite Middleware
      • Additional Components
        • AI Service
        • OX Guard UI
        • Switchboard
    • Helm Charts
      • AI-Service documentation
      • App Suite Stack Chart
      • Helm Chart core-cacheservice
      • Helm Chart core-documentconverter
      • Helm Chart core-imageconverter
      • core-mw
      • Switchboard
  • Release 8.49
  • Release 8.48
  • Release 8.47LTS
  • Release 8.46
  • Release 8.45
Maintained. Older releases are best effort.
Upcoming
Not released yet
LTS
Long-term support branch

App Suite Middleware

8.50.180 - 2026-08-13

Fixed

  • Fall back to database when the folder cache transiently returns null so folder look-ups keep their non-null-or-throw contract (support#1599)

8.50.179 - 2026-08-12

Changed

  • Update the documentation-properties plugin to 6.0.3 so the plugin classpath survives jackson 2.22.1 from plugin-bom 2.2.0

Fixed

  • Do not purge calendar data when a folder cannot be resolved (support#1599)

8.50.178 - 2026-08-12

Fixed

  • Invalidated grantee caches on shared-account/deputy revocation so revoked shared accounts and mailboxes no longer linger (support#1126)

8.50.177 - 2026-08-11

Fixed

  • Do not report a failed IMAP quota look-up as exceeded quota (support#1636)

8.50.176 - 2026-08-08

Fixed

  • Release the per-session JMAP trace appender when the access is retired - /appsuite/platform/middleware (core#11)

8.50.175 - 2026-08-07

Fixed

  • Keep writing a datamining report when a database schema is unreachable (support#1618)
  • Check attachment quota and max mail size against the spooled attachment size (support#1627)

8.50.174 - 2026-08-06

Fixed

  • Close the static service registry mock that leaked into other POP3 tests
  • Correct the misspelled mail capability cache idle time property, keeping the old name as a fallback
  • Expire a failed or degraded mail server capability probe instead of caching it forever

8.50.172 - 2026-08-05

Added

  • Documentation for the mail account property infixes
  • Honor the ".secondary" property infix alongside ".primary" for mail accounts

Fixed

  • Treat empty and whitespace-padded mail account property values correctly
  • Resolve allowFetchSingleHeaders per mail account in the conversation view

8.50.170 - 2026-08-03

Fixed

  • Release the IMAP debug logger on every path that gives up an IMAP session (#5)

8.50.168 - 2026-08-01

Fixed

  • IMAP command injection through user flags and the headers request parameter

8.50.166 - 2026-07-31

Fixed

  • Resolve standard folders of shared accounts under the accessing user's perspective (support#1543)
    • Synthetic shared-account sessions carry no credentials by design, so config-tree settings that require an individually authenticated mail access are skipped for them now. Instead, a shared account's default folders are resolved through the session user's own view on the associated mail account, using stored full names first and a connected mail access as fallback.

8.50.165 - 2026-07-30

Added

  • Redirect reads to the master while a read replica reports broken or excessive replication lag (#4)

Fixed

  • Restore replica staleness check by tracking the replication monitor counter process-locally (support#1599)

8.50.164 - 2026-07-30

Changed

  • SCR-1749: Upgraded Grizzly to 5.0.2

8.50.163 - 2026-07-29

Fixed

  • Always provide the mail's display date, also for nested messages (support#1598)

8.50.162 - 2026-07-28

Fixed

  • Register the globaldb utf8mb4 package in the Liquibase custom-change manifest header

8.50.157 - 2026-07-23

Fixed

  • Report exact attachment sizes for composition space drafts (support#1585)

8.50.155 - 2026-07-23

Fixed

  • Do not queue messages for a second, delayed publication when message buffering is disabled (support#1584)

8.50.154 - 2026-07-23

Fixed

  • Obtain property "com.openexchange.imap.considerSubscribedInListExtended" via IIMAPProperties to gain config-cascade and per-account support (support#1543)

8.50.153 - 2026-07-23

Fixed

  • Never skip sender validation when transmitting via action=new (support#1531)
  • Propagate affected folders in folder map invalidation messages so remote nodes drop them for every user (support#1584)

8.50.152 - 2026-07-22

Fixed

  • Property "com.openexchange.imap.considerSubscribedInListExtended" (true/false/probe) to obtain subscription state from separate LSUB when the \Subscribed attribute of LIST-EXTENDED responses is untrustworthy (support#1543)

8.50.151 - 2026-07-22

Fixed

  • Repoint openapi plugins to gitlab.com registry and bump to latest
  • Tolerate missing parent folder during IMAP default folder check (support#1129)

8.50.150 - 2026-07-22

Fixed

  • Validate From/Sender ownership on mail bounce (support#1531)

8.50.149 - 2026-07-22

Fixed

  • Throw FOLDER_NOT_FOUND instead of NPE for missing calendar folder (support#1577)
  • Single-pass, escaping URI token compression to keep proxy registrations round-trip safe (support#1582)

8.50.148 - 2026-07-22

Fixed

  • Throw FOLDER_NOT_FOUND instead of NPE for missing calendar folder (support#1577)
  • Guard composite LDAP filter construction against non-representable search term operands (support#1578)

8.50.147 - 2026-07-21

Fixed

  • Drop RFC 2965 $-prefixed framing cookies in servlet bridge (support#1560)

8.50.146 - 2026-07-21

Fixed

  • Await a concurrently running sibling bulk pre-cache instead of skipping it (support#1522)

8.50.145 - 2026-07-21

Fixed

  • Await a concurrently running sibling bulk pre-cache instead of skipping it (support#1522)

8.50.143 - 2026-07-21

Fixed

  • Reuse GETACL results across folder-tree rebuilds (support#1522)

8.50.140 - 2026-07-16

Changed

  • SCR-1793: Harden Redis connection lifecycle against stale/orphaned connected clients

Fixed

  • Populate internal user id consistently in results from LDAP contacts provider (support#1542)
    • The context id required to resolve a requested internal user id is fetched implicitly again throughout the search- and auto-complete flows, and the caching layer no longer exposes the internal 0 sentinel, no longer overrides live-resolved identifiers with unresolvable cached data, and yields complete fallback results.
  • Store DB-assignment and schema-update-state cache entries as plain per-context/per-schema keys instead of one global group hash (support#1562)

8.50.139 - 2026-07-14

Fixed

  • Correct case-insensitive match and quieten expected 'mailbox does not exist' on MYRIGHTS

8.50.138 - 2026-07-14

Fixed

  • Scoped Entity2ACL look-up caches to the requesting session and account

8.50.137 - 2026-07-14

Fixed

  • Keep emitting user_id 0 for non-user contacts to preserve HTTP-API compatibility (support#1438)

8.50.136 - 2026-07-10

Fixed

  • Bump About-box default copyright year to 2026 (support#1553)

8.50.135 - 2026-07-10

Fixed

  • Avoided doomed GETMETADATA on virtual namespace placeholders (support#1543)
  • Restored xs:date/nillable for SOAP birthday and anniversary (support#1551)

8.50.134 - 2026-07-10

Fixed

  • Normalize ACL rights before checking their equality (core#522)
  • Avoided doomed GETMETADATA on virtual namespace placeholders (support#1543)
  • Restored xs:date/nillable for SOAP birthday and anniversary (support#1551)

8.50.133 - 2026-07-08

Fixed

  • Preserved shared/deputy mailbox visibility with consolidated LIST-EXTENDED folder listing (support#1543)

8.50.132 - 2026-07-02

Fixed

  • PBSR-1766: Indicate correct account prefix for folder ids in mail filter rules of non-primary accounts
  • Detect synthetic sessions by origin, not instanceof
    • A ServerSessionAdapter wrapping a GeneratedSession is not instanceof GeneratedSession, so scheduling transport skipped its no-reply fallback and tried to OAuth-authenticate a token-less session. Check Origin.SYNTHETIC.

8.50.131 - 2026-07-02

Fixed

  • Detect synthetic sessions by origin, not instanceof
    • A ServerSessionAdapter wrapping a GeneratedSession is not instanceof GeneratedSession, so scheduling transport skipped its no-reply fallback and tried to OAuth-authenticate a token-less session. Check Origin.SYNTHETIC.
  • Rename changesharedaccount CLI tool documentation and help text to updatesharedaccount
  • Calendar notifications not sent for delegate edits on shared calendars (support#1439)

8.50.129 - 2026-06-25

Changed

  • Add owner-trace diagnostic logging for filestore snippets (support#1329)

Fixed

  • Make a failed scheduled-mail failure-notification visible (support#1515)
  • Reuse one IMAP connection per endpoint when serializing folder counts (support#1522)

8.50.128 - 2026-06-23

Fixed

  • Add opt-in overload protection for cache-outage DB stampedes (support#1517)

8.50.127 - 2026-06-23

Fixed

  • ExistingUISettingsSecret checksum and document existing*Secret values
    • Backport of main commit ab96e610c2f to stable-8.50.
    • The existingUISettingsSecret was missing from core-mw.existingSecretsChecksum, so content changes to that secret did not trigger a rolling restart unlike the other existing* secrets. Added the missing block.
    • Also added a guide on the existing*Secret values to the chart README, clarified the additive-vs-replace behavior in the values.yaml comments, and bumped the chart version to 6.21.1.

8.50.126 - 2026-06-23

Fixed

  • Quota retrieval fails on global DB due to missing committedFiles column (support#1518)

8.50.125 - 2026-06-19

Fixed

  • Add missing import for LogProperties in TransportPerformer
  • Retry/back-off for retryable mail access errors when transporting scheduled mails (support#1495)
  • Stop DB heart-beat after a failed keep-alive instead of retrying on a dead connection (support#1501)

8.50.124 - 2026-06-03

Fixed

  • CP-572: Avoid full Redis key-space scan when closing sessions by user/context filter

8.50.121 - 2026-06-01

Added

  • SCR-1714: PBSR-1613: REST Interface to Retrieve Effective Shared Account Permissions

Fixed

  • Liquibase migration failed on MariaDB with "Unknown column 'EXPRESSION'"

8.50.120 - 2026-05-30

Fixed

  • IOL-2841: Reconnect mail access when attachment handling takes too long (2)

8.50.119 - 2026-05-29

Fixed

  • IOL-2841: Reconnect mail access when attachment handling takes too long

8.50.118 - 2026-05-29

Added

  • Translation updates for 8.50
    • all languages but Latvian

8.50.117 - 2026-05-28

Fixed

  • Merge schema lists in Java to avoid collation mismatch in update task listing (support#1467)

8.50.116 - 2026-05-28

Fixed

  • Recover from read-only replica after Redis Sentinel fail-over (support#1482)

8.50.115 - 2026-05-28

Fixed

  • Data: URL inline images rendered with empty src in display path (support#931)
  • Recover from read-only replica after Redis Sentinel fail-over (support#1482)

8.50.112 - 2026-05-27

Added

  • PBSR-1476: Expose 'io.ox/core//categories' JSlob from shared account entities
  • PBSR-1576: Expose setting for 'Sent' folder preference of shared accounts
  • PBSR-1591: Expose simple overall "unread" indicator for mail account root folders if supported
    • SCR-1692: Additional Field 'com.openexchange.imap.rootFolderStatus' for Mail Account Root Folders
  • PBSR-1677: Overall "set" Method to Apply all Shared Account Permissions for Target
  • PBSR-1599: New Action 'hasActive' in Module 'mailfilter/v2'
    • SCR-1695: In order to get a quick information if there are currently specific mail filter rules active or not for an account, the new action hasActive is introduced in module mailfilter/v2 of the HTTP API
  • PBSR-1564: User can send Automatic Email Replies for every received email
    • SCR-1696: New Configuration Property 'com.openexchange.mail.filter.options.vacation.minimumInterval.seconds' has been introduced
  • SCR-1711: Add validateSession mail action for the JMAP-IMAP proxy
  • Upgrade Grizzly 2.4 → 4.0.2 + jakarta.servlet bridge-only consolidation
  • "davx5manual" onboarding scenario for manual DAVx5 Select setup
  • Documentation for com.openexchange.keystore.k8s.* properties
  • Documentation for customizable email templates
  • Expose "davx5" capability when both DAVx5 onboarding scenarios are enabled
  • HTTP API action mail?action=getByGuid to resolve a mail by backend GUID
  • Resolve plist signing keystore via KeyStoreService for k8s secret rotation
  • Translation updates version 8.49: cs_CZ, da_DK, de_DE, el_GR, en_GB, es_ES, es_MX, fi_FI, fr_CA, fr_FR, hu_HU, it_IT, ja_JP, lv_LV, nl_NL, pl_PL, pt_BR, ro_RO, ru_RU, sk_SK, sv_SE, tr_TR, zh_CN, zh_TW
  • Optional aggressive ACL cleanup when revoking a deputy permission (support#1004)

Changed

  • PBSR-1591: Rename folder field column from "com.openexchange.imap.rootFolderStatus" to "com.openexchange.mail.rootFolderStatus"
  • Introduced trace logging across free/busy pipeline (core#462)
  • Introduced simple SMTP connection pool & Use PIPELINING extension for MAIL-FROM and RCPT-TO commands (core#497)
  • Added TRACE logging for event data loading and post-processing (support#1247)
  • Added possibility to log all connection-using thread on "too many connections" error (support#1363)
  • Register singleton service com.openexchange.hazelcast.DataMemberService to advertise at least one data member is available in Hazelcast cluster (support#1402)

Fixed

  • CXF stub init stalls on ?wsdl GETs after Grizzly 4 / jakarta-servlet bridge migration
  • IAE-133: Orderly apply punycode decoding for OAUTHBEARER user name if "com.openexchange.mail.filter.punycode" is set to "true"
  • PBSR-1591: Follow-up — rename test getter to match renamed schema
  • SOAP test client stalls on ?wsdl fetch when the dev reverse proxy accepts h2c
  • Strings.splitLines must drop trailing empty entries
  • Added missing seconds to vacation mail filter api response
  • Ensure sort_by_first_name is present
  • Movecontextdatabase failed with "Table '<oxdb>.context' doesn't exist" (core#509)
  • Orphaned mail accounts with oauth=0 disappear from account list (support#1366)
  • Properly handle null values in jslob storage
  • User proper order for charset and collation
  • Limit number of concurrent transport attempts for scheduled mails (core#497)
  • Corrected database query for loading permission records into cache (core#501)
  • Prevent possible IMAP injection vulnerability (core#502)
  • Support 8bit messages (core#503)
  • Invalidate cached MailAccess instances when mail account is changed (core#504)
  • Login rate limit not effective due to greedy token refill (core#507)
  • Address headers emitted as raw UTF-8 instead of Q-encoded (core#510)
  • NPE in OXFolderManagerImpl.parseTruncated() for truncated 'meta' folder column; enlarge meta BLOB to MEDIUMBLOB (core#512)
  • Interpret "PRIORITY:0" as undefined priority during VTODO import (core#515)
  • Externalize data: URL inline images into managed files (support#931)
  • Re-verify cached schema state when blocking updates remain pending (support#1162)
  • Movecontextdatabase fails on large contexts due to configdb wait_timeout (support#1218)
  • Also include whole query for tokenized auto-complete if applicable (support#1357)
  • Reduce configdb pressure of nightly cleanup runs (support#1363)
  • Follow up, double-check if context exists (support#1406)
  • Added missing "limit" parameter to HTTP-API documentation for /mail?action=search (support#1408)
  • Task search did not evaluate categories filter (support#1434)
  • Remove hardcoded '/ui' from internal share link path (support#1437)
  • Serialize INTERNAL_USERID as null for non-user contacts — (support#1438)
  • Incorrect From/To on reply when an alias is assigned to multiple users in the same context (support#1440)
  • Scheduled mail date_to_send returns null in action=all when IMAP server drops $CurrentlyScheduled user flag (support#1444)
  • Sanitize illegal filename characters when saving mail attachments to Drive (support#1459)
  • Send failure notification for scheduled mails even when transport setup fails (support#1460)
  • Use more generic error code in failure notification to avoid possibly exposing sensitive information (support#1461)
  • Surface legacy single-schema pools in listdatabaseschema and runallupdate (support#1462)
  • Harden Redis Failsafe defaults to prevent bulkhead-full floods (support#1464)
  • Escape user-derived values in LDAP bind request templates (support#1465)
  • Wrap multipart/encrypted in outer multipart/mixed when extra clear-text parts ride along (support#1469)
  • Restore urn:liquibase namespace tolerance under Liquibase 4.33 (support#1475)
  • DB pool exhaustion during autoscaler scale-up (support#1477)
Prev
App Suite UI
Next
Additional Components