[Git][security-tracker-team/security-tracker][master] Track fixed version for roundcube issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon May 25 05:51:09 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a7cf1e9f by Salvatore Bonaccorso at 2026-05-25T06:50:23+02:00
Track fixed version for roundcube issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -71,35 +71,35 @@ CVE-2026-9360 (A security flaw has been discovered in Edimax EW-7438RPn 1.28a. A
CVE-2026-4372 (A critical remote code execution vulnerability exists in all versions ...)
NOT-FOR-US: HuggingFace transformers
CVE-2026-XXXX [Code injection vulnerability via code evaluation support in LDAP autovalues option.]
- - roundcube <unfixed> (bug #1137507)
+ - roundcube 1.6.16+dfsg-1 (bug #1137507)
NOTE: https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
NOTE: https://github.com/roundcube/roundcubemail/commit/ea1798a6fbf060abcc0ba73b2435036bf8016a5a
CVE-2026-XXXX [Pre-auth arbitrary file delete via redis/memcache session poisoning bypass]
- - roundcube <unfixed> (bug #1137507)
+ - roundcube 1.6.16+dfsg-1 (bug #1137507)
NOTE: https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
NOTE: https://github.com/roundcube/roundcubemail/commit/703318e6a59515b73b0d8aa2a91e346b02f56baa
CVE-2026-XXXX [Bypass of remote image blocking via CSS var().]
- - roundcube <unfixed> (bug #1137507)
+ - roundcube 1.6.16+dfsg-1 (bug #1137507)
NOTE: https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
NOTE: https://github.com/roundcube/roundcubemail/commit/852350486b88b35b8544e8a630fad89e99e2150a
CVE-2026-XXXX [Local/private URL fetch bypass when remote resources were not allowed]
- - roundcube <unfixed> (bug #1137507)
+ - roundcube 1.6.16+dfsg-1 (bug #1137507)
NOTE: https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
NOTE: https://github.com/roundcube/roundcubemail/commit/7b52353653a67e6073b97d70eb94047132b78556
CVE-2026-XXXX [SSRF bypass via specific local address URLs.]
- - roundcube <unfixed> (bug #1137507)
+ - roundcube 1.6.16+dfsg-1 (bug #1137507)
NOTE: https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
NOTE: https://github.com/roundcube/roundcubemail/commit/cb3fc9041e91640ba9ba49ee7b2147c176ebf5a1
CVE-2026-XXXX [Pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass.]
- - roundcube <unfixed> (bug #1137507)
+ - roundcube 1.6.16+dfsg-1 (bug #1137507)
NOTE: https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
NOTE: https://github.com/roundcube/roundcubemail/commit/87124cc7136a48b5fa9d2b40dfead6e9dcaeaf4b
CVE-2026-XXXX [CSS injection bypass in HTML sanitizer via SVG <animate attributeName="style">.]
- - roundcube <unfixed> (bug #1137507)
+ - roundcube 1.6.16+dfsg-1 (bug #1137507)
NOTE: https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
NOTE: https://github.com/roundcube/roundcubemail/commit/58e5263f341e6a418774fb6d2643669a3c4d8a27
CVE-2026-XXXX [Stored XSS/HTML/CSS injection in subject field of the draft restore dialog]
- - roundcube <unfixed> (bug #1137507)
+ - roundcube 1.6.16+dfsg-1 (bug #1137507)
NOTE: https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
NOTE: https://github.com/roundcube/roundcubemail/commit/a21519187873ce962db029b6ff68e47bd7f3fd8a
CVE-2026-9359 (A vulnerability was identified in Edimax EW-7438RPn 1.28a. Affected by ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a7cf1e9f99d90b3f2301657d92c0c89d8ccda239
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a7cf1e9f99d90b3f2301657d92c0c89d8ccda239
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260525/df87369c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list