| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-07-29 | 1.3 kB | |
| Release 4.1.4 source code.tar.gz | 2026-07-29 | 7.1 MB | |
| Release 4.1.4 source code.zip | 2026-07-29 | 8.4 MB | |
| Totals: 3 Items | 15.5 MB | 0 | |
Incompatible changes
- Build: rspamd now links a single shared jemalloc instance per process and refuses a static-only jemalloc — duplicated allocators caused segfaults at startup
Features
- WebUI: read-only users can now access the Selectors tab and the Errors history
Bug fixes
- Controller (critical): fail closed on a malformed password hash — previously any password was accepted
- Regexp engine: fix a PCRE2 match-data leak on invalid UTF input, bound the heap a single match can use, stop
re:matchn()looping forever on empty matches, avoid reading past the end of a bounded pattern when generating ids, and propagate the regexp data limit to named scopes - Message processing: consult the Lua URL filter at most twice per user field instead of once per byte, and bound the words retained per message with a message-wide budget
- CSS: skip comments iteratively in the tokeniser, avoiding a stack overflow on many sequential comments
- Startup: release actrie GLib allocations with
g_free, fixing a startup segfault with jemalloc - rspamadm: resolve SRV-based upstreams and wait for storages in
fuzzy_pingandfuzzy_hash
Full changelog: https://github.com/rspamd/rspamd/compare/4.1.3...4.1.4