[From nobody Mon Aug 10 23:07:11 2026
Received: (at submit) by bugs.debian.org; 10 Aug 2026 12:31:01 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-112.8 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIMWL_WL_HIGH,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,
 FOURLA,FROMDEVELOPER,MD5_SHA1_SUM,PGPSIGNATURE,SPF_HELO_NONE,SPF_PASS,
 USER_IN_DKIM_WELCOMELIST,WEBMAIL autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 48; hammy, 150; neutral, 109; spammy,
 0. spammytokens:
 hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin,
 0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311,
 0.000-+--H*RT:311, 0.000-+--H*RT:108
Return-path: &lt;guilhem@debian.org&gt;
Received: from stravinsky.debian.org ([2001:41b8:202:deb::311:108]:42538)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;guilhem@debian.org&gt;) id 1wtP9g-007ft6-2i
 for submit@bugs.debian.org; Mon, 10 Aug 2026 12:31:00 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; 
 s=smtpauto.stravinsky;
 h=X-Debian-User:Content-Type:MIME-Version:Message-ID:
 Subject:To:From:Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:
 Content-Description:In-Reply-To:References;
 bh=u7usC+xC2g9GBz9iqhABgae8FoJKnaJLJAuFgRKE1+I=; b=H4/OB7m45lWUjUTP0oh6/Vq0al
 WqXqMzGaZLrqUxsGwNSC1mKVn234hB4/Hx2Ll8u86+Qz1zhJzgL5JFuJSoxkJnN3Oa7kke/iJOkf9
 OIBofHRjrckPWE8hw7/cFhyNTWfdheDO/VN0DydcbFvO2bYQ7/0YXqVFQNZcm/v7BSN3ZbYivQkOf
 4MDYI7VIZcp/1LUOqb7Hpb0Eo4pWKaDqRonGGnIyHtPr4jTfifD6EqpyUow9DCgboGb7Xkg9xvX/A
 uK4doP/oSwbl2NYsTFuo3ispaASyFH53v3+JAXYbTobIqBbiIDfApzipiZ3lhc1l/ip84pBpBV0RP
 2r0KLzlA==;
Received: from authenticated-user by stravinsky.debian.org with esmtpsa
 (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;guilhem@debian.org&gt;) id 1wtP9e-002kab-0v;
 Mon, 10 Aug 2026 12:30:59 +0000
Received: by localhost.localdomain (Postfix, from userid 1000)
 id 32C7042109F; Mon, 10 Aug 2026 14:30:56 +0200 (CEST)
Date: Mon, 10 Aug 2026 14:30:56 +0200
From: Guilhem Moulin &lt;guilhem@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: roundcube: Multiple security vulnerabilities
Message-ID: &lt;annEbPAj4_52a9h-@debian.org&gt;
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha512;
 protocol=&quot;application/pgp-signature&quot;; boundary=&quot;rmLTfvixBEuf1n0q&quot;
Content-Disposition: inline
X-Reportbug-Version: 13.2.0+nmu1
X-Debian-User: guilhem
Delivered-To: submit@bugs.debian.org

--rmLTfvixBEuf1n0q
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Source: roundcube
Version: 1.6.17+dfsg-1
Control: found -1 1.6.17+dfsg-0+deb13u1
Control: found -1 1.6.5+dfsg-1+deb12u10
Control: found -1 1.4.15+dfsg.1-1+deb11u10
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: Debian Security Team &lt;team@security.debian.org&gt;

Roundcube webmail upstream has recently released 1.6.17 [0] which fixes
the following security vulnerabilities:

 1. Content proxied by the css proxy is not validated validation
    https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd0398=
4220dc9709e8e0de43b
 2. SSRF bypass via specific local address URLs using 100.64.0.0/10 and
    fe80::/10 subnets
    https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e03=
4c4f40d6a6546c21223
 3. SSRF filter bypass via various forms of nip.io/sslip.io hostnames
    evading is_local_url() check
    https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be75715=
4f94548a9ba903455c9
 4. Remote content blocking bypass via unclosed url() in a FuncIRI
    attribute
    https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9=
a33d30880d290b5591b
 5. LDAP filter injection via unescaped %u/%fu/%d substitution into the
    `search_filter`
    https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916=
feb4e019d2828924540
 6. Arbitrary sieve script injection via a filter rule name bypassing
    `managesieve_disabled_actions`
    https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376=
c072bb5ca5ded64495e
 7. RCE in the `cmd_learn` driver of markasjunk plugin
    https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a695=
68cba897f8f4223d9cd
    Follow-up: https://github.com/roundcube/roundcubemail/commit/495d211638=
f222336b20f4744545c53712426c2a
 8. IMAP command injection via mail search and LITERAL+ byte-count
    desynchronization
    https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd0=
0041c7086c40e1793ea
 9. The modoboa driver of the passwd plugin leaks an authentication
    token to a user-controlled host
    https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bd=
a5bcc82f9c682cf804c
 10. Stored XSS in =E2=80=9CAdd to address book=E2=80=9D action
     https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6=
880ae303e740f0804fe8
 11. HTML/CSS sanitization bypass via SVG animate `by` attribute
     https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9=
bb03599abf754c33a33f

(Using severity=3Dgrave due to issues #7 and #9, although they are
specific to plugins which are not enabled by default.)

AFAIK no CVE-ID have been published for these issues.  I'll request some
later today unless someone beats me to it.
--=20
Guilhem.

[0] https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3

--rmLTfvixBEuf1n0q
Content-Type: application/pgp-signature; name=signature.asc

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmp5xGwACgkQ05pJnDwh
pVIlDA//c0czi3A6UsgRJJcOvW/eIeoVJu9IFMcGlxIb4d/7BLpMBH2sGqNCIoRO
UHDfh6PPnTokb4N2kznRDD0DlQfFtGoQzNFDJvPp8X1uMXhH0oPGLKSKVicpzrd8
O/03d/zy3NOYssV2s4z5Rh8EOFyBq6dKOUwbQwzfcX4bjfSXCqeNv/UYa07Ogf4Y
TO2MY4gYHi6juu3NxR/fgeMl57E/3FYt/Qzf8FlKz9HizzZHMOkdLqRHO+vOaGbK
X69HEoA5KFkBy1xpMfqaBjKbGIQ4kaDI2KjbeQWTxsScov2mJETX6GBZD7YlprPy
rXj7wiTjiuSRG4J9NJ8KAYn6fXm326lnEpTUOCbal5IzFWF4+TOKNPhwaGX2IU/g
qu7Et13+ZB+lWVyPxwQxzfhLWL1wpGcAYmA/SEQ59m1GUKOJ+neLhvMNXRKOk0Kh
ev7JHKKg65hXESbwjxyldqO5/w+YM+kK0Z3czi8Ecxt5KVYD9VaBOgzrzg6MbEz5
W8nsjAtDvWr/Mzb7876jnoAdZgfPe5CAK1SWKGw2vsdGmfN6G+6xza97aM1GdM33
t1+JwdQPgzO76muifHaZON/21xzqyrDl6tSZgisF+Hx99SokpXD/xDqnM+zX6dgP
EkFC3hpymKAduVnplIV+SOKfr4gtV7SEUWATD3rEMTowABJgMPg=
=yaPG
-----END PGP SIGNATURE-----

--rmLTfvixBEuf1n0q--
]