Select your language

10 Aug 2026

Bearsampp August Security Upgrade released

Security release!

This is a security fix with several module security fixes included, including php both in the core engine and in modules for php 8.2, 8.3, 8.4, & 8.5


10 Aug 2026

Xlight 3.9.5 Security Release

Security release!

3.9.5(2026-7-1)

  • Fixed three security vulnerabilities.
  • Add support for ECDH Key Exchange algorithm (ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521).
  • Add support for AES-GCM encryption algorithm (This email address is being protected from spambots. You need JavaScript enabled to view it.,This email address is being protected from spambots. You need JavaScript enabled to view it.).
  • Add support for (ETM) Encrypt-then-MAC hmac algorithm (This email address is being protected from spambots. You need JavaScript enabled to view it.,This email address is being protected from spambots. You need JavaScript enabled to view it.).
  • Fixed a few GUI bugs.

09 Aug 2026

Mailpit 1.30.7 Released

Chore

  • Add software license information (#724)
  • Update Go dependencies
  • Update node dependencies
  • Update GitHub Actions dependencies

Fix

  • Database lock when delete request contains duplicate IDs (#723)

Test

  • Add tests for requests containing duplicate & invalid IDs
09 Aug 2026

PHP 8.5.9, 8.4.24, 8.3.33 & 8.2.33 Security Release!

Security release!

  • GD:
    • Upgrade libgd. (CVE-2026-9672)
  • PGSQL:
  • Phar:
    • Fixed inconsistent handling of the magic ".phar" directory. Paths such as "/.phar" remain protected, while non-magic paths that merely start with ".phar" are handled consistently across file and directory creation, copying, ArrayAccess, stream lookup, directory iteration and extraction.
    • Fixed GHSA-vc5h-9ppw-p5f3 (Crash via recursive symlinks). (CVE-2026-7260)
06 Aug 2026

Mailpit 1.30.6 Security Release!

Security release!

Security

  • Prevent WebSocket CORS origin check bypass via percent-encoded path (GHSA-8r62-w5wh-fc5m)
  • Implement POP3 failed login tracking and disconnect after multiple attempts
  • Redact POP3 password in debug logs to prevent credential exposure

Chore

  • Add ReadHeaderTimeout to HTTP server configuration
  • Update node dependencies
  • Update Go dependencies
  • Update caniemail database
  • Update Github Actions dependencies

Fix

  • Prevent protocol desynchronization by draining oversized message data
  • Prevent marking already deleted POP messages for deletion
  • Ensure deleted POP3 messages are excluded from LIST and STAT commands
  • Update content type handling for attachments to ensure proper file downloads
  • Sanitise active Content-Type in attachment downloads
  • Escape file names in Content-Disposition header for thumbnail responses
  • Allow passwords with spaces in POP3 authentication
  • Implement dot-stuffing for TOP commands in POP3 server
  • Correct order of setting headers and writing HTTP error response
  • Handle client disconnection during DATA read with appropriate logging in SMTPD server (#721)

Test

  • Add brute force POP3 login protection test
  • Add more WebSocket CORS tests
  • Enhance CORS middleware tests for HTML preview route handling
06 Aug 2026

Powershell 7.6.4 Released!

Update to .NET SDK 10.0.302

  • Update branch for release (#27685)
  • Avoid calling credential provider for public feed for Wix (#27666)
  • Separate NuGet publish into its own stage after pushing the git tag (#27652)
  • PMC: Download deb_arm artifact to ensure package is available for PMC publish flow (#27653)

25 Jul 2026

Mailpit 1.30.5 Security Release!

Security release!

Security

Chore

  • Update Go dependencies
  • Update node dependencies
20 Jul 2026

Bearsampp 4yr anniversary Anthem released

In honor of our 4yr anniversary I'm happy to announce the release of our Anthem song. Hope everyone enjoys it. Was fun to create.

16 Jul 2026

Bearsampp 2026 LTS Release



Bearsampp year 4, 2026 LTS release is a major upgrade.
features major performance upgrades with sub 1 minute start and stop times
100% powershell based consoles featuring oh-my-posh for pathing layout with git version support
core engine upgraded to php 8.5.8
more developer friendly with sandbox improvements and customizations.
CI testing for critical module pre-release testing.
full bearsampp user friendly documentation available.
fixed long standing database bin paths missing issue
several engine improvements and redesign
consolez, adminer & svn modules support dropped.

SECURITY FIXES:
most modules have had severe grade security upgrades including apache & php
modernized several libraries to help eliminate possible security vulnerabilities
full ssl compliance resulting in true "lock" mode in all major browsers

Features:
New quickpick enhanced mode provides 2 click installation of modules.
with 1 click installs coming soon.
automatic ssl certificate creation of all vhosts.
automatic rootCA creation to support authenticated SSL ability.
100% gradle build system for all modules & core.
engine is now 100% php 8.5.8 ready

Our Supporters

Sorry, this website uses features that your browser doesn't support. Upgrade to a newer version of Firefox, Chrome, Safari, or Edge and you'll be all set.