[Git][security-tracker-team/security-tracker][master] roundcube issues fixed via unstable upload

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 11 05:31:07 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
790a9e9e by Salvatore Bonaccorso at 2026-08-11T06:30:16+02:00
roundcube issues fixed via unstable upload

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -498,38 +498,38 @@ CVE-2026-68871 (The Yandex Lockbox secrets backend in Apache Airflow's Yandex pr
 CVE-2026-68872 (The AWS Systems Manager Parameter Store and Secrets Manager backends i ...)
 	NOT-FOR-US: Apache Airflow provider
 CVE-2026-XXXX [Content proxied by the css proxy is not validated validation]
-	- roundcube <unfixed> (bug #1144059)
+	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b (1.6.18)
 CVE-2026-XXXX [SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 subnets]
-	- roundcube <unfixed> (bug #1144059)
+	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223 (1.6.18)
 CVE-2026-XXXX [SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check]
-	- roundcube <unfixed> (bug #1144059)
+	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9 (1.6.18)
 CVE-2026-XXXX [Remote content blocking bypass via unclosed url() in a FuncIRI attribute]
-	- roundcube <unfixed> (bug #1144059)
+	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b (1.6.18)
 CVE-2026-XXXX [LDAP filter injection via unescaped %u/%fu/%d substitution into the `search_filter`]
-	- roundcube <unfixed> (bug #1144059)
+	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540 (1.6.18)
 CVE-2026-XXXX [Arbitrary sieve script injection via a filter rule name bypassing `managesieve_disabled_actions`]
-	- roundcube <unfixed> (bug #1144059)
+	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e (1.6.18)
 CVE-2026-XXXX [RCE in the `cmd_learn` driver of markasjunk plugin]
-	- roundcube <unfixed> (bug #1144059)
+	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd (1.6.18)
 	NOTE: Follow-up: https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a (1.6.18)
 CVE-2026-XXXX [IMAP command injection via mail search and LITERAL+ byte-count desynchronization]
-	- roundcube <unfixed> (bug #1144059)
+	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea (1.6.18)
 CVE-2026-XXXX [The modoboa driver of the passwd plugin leaks an authentication token to a user-controlled host]
-	- roundcube <unfixed> (bug #1144059)
+	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c (1.6.18)
 CVE-2026-XXXX [Stored XSS in "Add to address book" action]
-	- roundcube <unfixed> (bug #1144059)
+	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8 (1.6.18)
 CVE-2026-XXXX [HTML/CSS sanitization bypass via SVG animate `by` attribute]
-	- roundcube <unfixed> (bug #1144059)
+	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f (1.6.18)
 CVE-2026-6791 (When expanding paths that begin with a tilde (~) followed by a usernam ...)
 	- glibc 2.43-3



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/790a9e9ea7b08e95e4c3d312fa97227f05b84491

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/790a9e9ea7b08e95e4c3d312fa97227f05b84491
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/dbc97f2d/attachment.htm>


More information about the debian-security-tracker-commits mailing list