# Postal 3.3.7 — v3.3.7 - Product: Postal (https://whatsnew.fyi/product/postal) - Vendor: Postal - Date: 2026-06-03 - Version: 3.3.7 - Original notes: https://github.com/postalserver/postal/releases/tag/3.3.7 - Permalink: https://whatsnew.fyi/product/postal/releases/3.3.7 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Prevent SSRF in outbound webhook and HTTP endpoint requests - **security** — Prevent SQL injection via condition keys - **fixed** — Stub IPv6 support in address guard IPv6 literal spec ##### [3.3.7](https://github.com/postalserver/postal/compare/3.3.6...3.3.7) (2026-06-03) ###### Bug Fixes * **http:** prevent SSRF in outbound webhook and HTTP endpoint requests ([11c9814](https://github.com/postalserver/postal/commit/11c9814474f956619da35e8385ef7fab9f304de0)) * **message-db:** prevent SQL injection via condition keys (GHSA-x2hq-rfpg-3xr5) ([4314a6e](https://github.com/postalserver/postal/commit/4314a6ec1e2812daa67dd20effd1db1769c1f8e8)) * **specs:** stub IPv6 support in address guard IPv6 literal spec ([029bfe0](https://github.com/postalserver/postal/commit/029bfe098d9b8c0b5cafc49eac33e767f5748cd3)) ###### Miscellaneous Chores * **deps:** upgrade rack & rails ([0445e5c](https://github.com/postalserver/postal/commit/0445e5c509870dfe9c16366c53dee3fc02ad3904)) * update security vulnerability reporting instructions ([8be1e27](https://github.com/postalserver/postal/commit/8be1e27fec489ab659ef5e909f705932028b1694))