View Issue Details

IDProjectCategoryView StatusLast Update
0006201SOGoBackend Calendarpublic2026-10-01 10:13
Reporterralfbergs Assigned To 
PrioritynormalSeverityminorReproducibilityalways
Status newResolutionopen 
Product Version5.12.5 
Summary0006201: Calendar invite: email has invalid message id
Description

When I send a calendar invite, the resulting email message has an invalid message id in the format Message-Id: <ae06c383-0f08-ba0a-682a-4db12d05fb49@example.org>> (note the duplicate "greater than" character!).

The integration is: Thunderbird using CalDav towards my mailcow server. Thunderbird is not sending the invite locally via SMTP, but the mailcow backend creates the invite and sends it.

More details here: https://github.com/mailcow/mailcow-dockerized/issues/7213

Steps To Reproduce
  1. Send a calendar invite via SOGo's CalDAV backend.
  2. Observe that an invalid message id was generated and used as described above.
TagsNo tags attached.

Activities

ralfbergs

ralfbergs

2026-05-26 19:11

reporter   ~0018487

Is there anything unclear about this ticket? I'm wondering why there is no acknowledgement since more than 2 weeks...

martinRaiola

martinRaiola

2026-10-01 10:13

reporter   ~0018557

Confirmed on SOGo 5.12.10 (mailcow image ghcr.io/mailcow/sogo:5.12.10-1). Reproducible every time.

== Scenario ==

  1. A user creates or updates an event with an external attendee in Thunderbird 140.x. The calendar is a SOGo CalDAV calendar:
    PUT /SOGo/dav/<user>/Calendar/personal/<uid>.ics -> 201 (create) / 204 (update)
  2. In the same second, SOGo sends the iMIP invitation to the attendees through the iTIP scheduler. In the Postfix logs it arrives via the SOGo submission service, from the SOGo container:
    postfix/sogo/smtpd: client=<sogo-container>, sasl_method=plain, sasl_username=user@example.org
  3. The generated header is malformed (extra '>'):
    postfix/cleanup: message-id=<698bda2b-b27d-5101-7f49-90cfcceb756e@example.org>>

== Impact ==
Microsoft 365 accepts the message, and echoes the malformed ID back in its reply, which proves the header goes out on the wire like this:
status=sent (250 2.6.0 <698bda2b-b27d-5101-7f49-90cfcceb756e@example.org>> [...] Queued mail for delivery)
But the invitation never reaches the recipient's inbox. Regular mail from the same users and the same server is delivered normally: well-formed Message-ID, SPF/DKIM/DMARC pass and aligned, 10/10 on mail-tester. In our logs, only the scheduler-generated invitations carry the extra '>'. The user's SOGo mail identity is a plain, valid "Full Name" + address, with no signature and no custom headers.

== Root cause ==
As analysed in https://github.com/Alinto/sogo/pull/407 and https://github.com/Alinto/sogo/pull/411: generateMessageID: takes the substring after the last '@' of the sender without sanitizing it. When the sender is "Full Name <user@example.org>", the trailing '>' becomes part of the domain. The same code path also allows header injection through the generated Message-ID.

== Fix ==
https://github.com/Alinto/sogo/pull/411 (open) fixes this. Could it be reviewed and merged? Related mailcow report: https://github.com/mailcow/mailcow-dockerized/issues/7213

== Workaround ==
Disable SOGo's e-mail notifications for appointments and let the client (Thunderbird) send the invitations over SMTP.

Issue History

Date Modified Username Field Change
2026-05-10 17:44 ralfbergs New Issue
2026-05-26 19:11 ralfbergs Note Added: 0018487
2026-10-01 10:13 martinRaiola Note Added: 0018557