[From nobody Sun Sep  6 16:07:07 2026
Received: (at submit) by bugs.debian.org; 6 Sep 2026 09:31:05 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-112.1 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIMWL_WL_HIGH,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,
 FOURLA,FROMDEVELOPER,MD5_SHA1_SUM,PGPSIGNATURE,SPF_HELO_NONE,SPF_PASS,
 USER_IN_DKIM_WELCOMELIST,WEBMAIL autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 60; hammy, 149; neutral, 101; spammy,
 1. spammytokens:0.993-1--enriched
 hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin,
 0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311,
 0.000-+--H*RT:311, 0.000-+--H*RT:108
Return-path: &lt;guilhem@debian.org&gt;
Received: from stravinsky.debian.org ([2001:41b8:202:deb::311:108]:39522)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;guilhem@debian.org&gt;) id 1x39DN-002h1o-0N
 for submit@bugs.debian.org; Sun, 06 Sep 2026 09:31:05 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; 
 s=smtpauto.stravinsky;
 h=X-Debian-User:Content-Type:MIME-Version:Message-ID:
 Subject:To:From:Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:
 Content-Description:In-Reply-To:References;
 bh=qF1i6tEpp8eTLiu7bcZeP/w33FfIqnWtm8KdGeQmAZk=; b=Mf5ycOoM+YQzpxjRWRKSpGTl4p
 5bFnWGoe4wd1P9+LvITp+r1e8f18MbXb87oQigGcVuCWbjDRvtFVWIQRPGizR7ofQdxLJ1x+Ckp8G
 mn5Jo553bSRo/lDy6+bMJ2KXkOq2IW/ijVuZWNwe5L0j/57WLDDMWAxcMLi4YRFgrT5VtNI1WvGyH
 nTv1Gb/DATti5nhOvFPpfmNsYjPQjTTt7QuyrwKPORM5pLHU7fRkdMoyx0oPT1qs6aTdZmWXk/wRP
 B9Szpk10P6C3XyOu6O9wPDX88XgTTosXXjNWf63PZm3Ft0FsifEeayhdkZRNtrrC2UHvWT2wmxPg5
 D1VYF4HQ==;
Received: from authenticated-user by stravinsky.debian.org with esmtpsa
 (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;guilhem@debian.org&gt;) id 1x39DL-000dgS-0U;
 Sun, 06 Sep 2026 09:31:03 +0000
Received: by localhost.localdomain (Postfix, from userid 1000)
 id 4F80F420AF8; Sun, 06 Sep 2026 11:31:01 +0200 (CEST)
Date: Sun, 6 Sep 2026 11:31:01 +0200
From: Guilhem Moulin &lt;guilhem@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: roundcube: Multiple security vulnerabilities
Message-ID: &lt;ap0y0-MPZEBHettO@debian.org&gt;
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha512;
 protocol=&quot;application/pgp-signature&quot;; boundary=&quot;bZLAqqFK59XA8CBo&quot;
Content-Disposition: inline
X-Reportbug-Version: 13.2.0+nmu1
X-Debian-User: guilhem
Delivered-To: submit@bugs.debian.org

--bZLAqqFK59XA8CBo
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Source: roundcube
Version: 1.6.18+dfsg-1
Control: found -1 1.6.18+dfsg-0+deb13u1
Control: found -1 1.6.5+dfsg-1+deb12u11
Severity: important
Tags: security upstream
X-Debbugs-Cc: Debian Security Team &lt;team@security.debian.org&gt;

Roundcube webmail upstream has just released 1.6.19 [0] which fixes
a new batch of security vulnerabilities:

  1. CSS declaration smuggling via un-encoded ampersand emission
     https://github.com/roundcube/roundcubemail/commit/8119eb061bffd6d967ee=
34e7bda21e20237fc1e0
  2. CSS property injection via body `background` attribute
     https://github.com/roundcube/roundcubemail/commit/030de9a4e58699a336f6=
2868017ea5271128c52f
     Follow-up: https://github.com/roundcube/roundcubemail/commit/3092bd9fb=
e65b243cf419352ddd3e53e5086c6cc
     Follow-up: https://github.com/roundcube/roundcubemail/commit/2869de81c=
94dee300df4193276cce588f10350e1
     Follow-up: https://github.com/roundcube/roundcubemail/commit/29beae728=
2135a3cd59a3945bd33ee8f904d6217
  3. Email header injection via bare CR in the subject field
     https://github.com/roundcube/roundcubemail/commit/73d864e06cb26000a37a=
d57ae439842a85b6690e
  4. Email header injection via C-escape \r in the recipient display name
     https://github.com/roundcube/roundcubemail/commit/d1238ef1fb0d66a9bacf=
6b01926b911f70515071
  5. Email header injection via identity=E2=80=99s organization field
     https://github.com/roundcube/roundcubemail/commit/11e5c9be0369e3b76bfe=
e2ae095f57532bae0f1f
  6. Zero-click stored XSS via TNEF MIME tag injection in the attachment URL
     https://github.com/roundcube/roundcubemail/commit/e4a0f82f4c648606de08=
67ee16b4a5f591ddbd69
     Follow-up: https://github.com/roundcube/roundcubemail/commit/7095e8d9d=
e10d2f8bb90c3639c582edf8e371d5c
  7. XSS in the HTML editor using text/enriched part content
     https://github.com/roundcube/roundcubemail/commit/1381bf5d7e4c595560ac=
f0228a2e68e471cefbd8
  8. Cross-user access in contact group membership (add/remove) in the SQL
     address book
     https://github.com/roundcube/roundcubemail/commit/19ba077a859b590bd886=
b437a6c8a3fdd8aa3952
  9. `is_local_url()` bypass via trailing-dot FQDN in stylesheet URL
     https://github.com/roundcube/roundcubemail/commit/9c4099bbff33062c8ab6=
e09d9b71e59dde295408
  10. Remote content blocking bypass via CSS escapes in FuncIRI attributes
      https://github.com/roundcube/roundcubemail/commit/9aa2b3f13c3707ac24a=
ee9899dd4ab693ee1e471
  11. Remote-content blocker bypass via SVG SMIL src animation
      https://github.com/roundcube/roundcubemail/commit/2bed9eeb5707636b8e5=
b915ae18d4d06b3971f31
  12. SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4
      addresses
      https://github.com/roundcube/roundcubemail/commit/05cc67c6bc501e2d818=
436dec571f9712f16ea61

AFAIK no CVE-ID have been published for these issues.  I'm currently
traveling but will request some next week unless someone beats me to it.
--=20
Guilhem.

[0] https://roundcube.net/news/2026/09/06/security-updates-1.6.19-and-1.7.4
    https://github.com/roundcube/roundcubemail/releases/tag/1.6.19

--bZLAqqFK59XA8CBo
Content-Type: application/pgp-signature; name=signature.asc

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmqdMtMACgkQ05pJnDwh
pVKthA/9E+Pm5tDOsS7+STnLhy0xf/nQVioXRZMdPIZ2Ha+34Jt8V8WtdJnhrCQH
TZ/DaGMb0ISrzMyXSGwJIJj3iZMXhln1rJIjRNU+gA2MpIvTcANEG/VTUqolxWF8
vFCq+6Op91+bNbaWRMcTDrDwaIcTJQz4W8QDU3h/b0XuI5EpCJQPobcD/HL+BJqW
hjHVS7aiN2umWS0tA2gN3q0v+qimSjPUFEYpHaxuEAPYLIYLTvmQKOC5Rpd22TOb
FQKPzTfPl4LVs2lp1u3zBM+uo/eV/jKTgzd0LWy4WEcX8q0GQVTf4yDrwOeCQV8+
qSUXvYWTMG8ZgvMF5eeXl2HTwYl6YQEr06RcEwjV3WldhZj3+HFwvrPOi4pzCC2j
zGqbaZEBpF2VaTQWYA2VAV3OlM68oKflevNgts0vew8yGHq9MHcNp1lWjEO1WIQ2
YI4AIfulskScJeX8xSMrT8BUh5q70S0xhwFMZ57yZtgTBbmKcLdgoWXgSdwdiBwt
PLQ906vw/OzqwnKOIuihCLU9h4VnFT/PklsEEquW9O5d1+2MVvHC/mRvOBIG5Eu9
cqiOYkQeVxavznaeEewf5WJxW51s8Gv6nFt7kkswMzngEoiziyEu8YdTES73MDJU
lKcSS4+/XxxJ5ftxkablWePhbB1mxsgc9WMPByR0tCQVVamJ+dg=
=OnZU
-----END PGP SIGNATURE-----

--bZLAqqFK59XA8CBo--
]