[Pkg-roundcube-maintainers] Bug#1144059: roundcube: Multiple security vulnerabilities

Salvatore Bonaccorso carnil at debian.org
Mon Aug 10 19:40:27 BST 2026


Hi Guilhem,

On Mon, Aug 10, 2026 at 02:30:56PM +0200, Guilhem Moulin wrote:
> Source: roundcube
> Version: 1.6.17+dfsg-1
> Control: found -1 1.6.17+dfsg-0+deb13u1
> Control: found -1 1.6.5+dfsg-1+deb12u10
> Control: found -1 1.4.15+dfsg.1-1+deb11u10
> Severity: grave
> Tags: security upstream
> Justification: user security hole
> X-Debbugs-Cc: Debian Security Team <team at security.debian.org>
> 
> Roundcube webmail upstream has recently released 1.6.17 [0] which fixes
> the following security vulnerabilities:
> 
>  1. Content proxied by the css proxy is not validated validation
>     https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b
>  2. SSRF bypass via specific local address URLs using 100.64.0.0/10 and
>     fe80::/10 subnets
>     https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223
>  3. SSRF filter bypass via various forms of nip.io/sslip.io hostnames
>     evading is_local_url() check
>     https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9
>  4. Remote content blocking bypass via unclosed url() in a FuncIRI
>     attribute
>     https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b
>  5. LDAP filter injection via unescaped %u/%fu/%d substitution into the
>     `search_filter`
>     https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540
>  6. Arbitrary sieve script injection via a filter rule name bypassing
>     `managesieve_disabled_actions`
>     https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e
>  7. RCE in the `cmd_learn` driver of markasjunk plugin
>     https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd
>     Follow-up: https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a
>  8. IMAP command injection via mail search and LITERAL+ byte-count
>     desynchronization
>     https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea
>  9. The modoboa driver of the passwd plugin leaks an authentication
>     token to a user-controlled host
>     https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c
>  10. Stored XSS in “Add to address book” action
>      https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8
>  11. HTML/CSS sanitization bypass via SVG animate `by` attribute
>      https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f
> 
> (Using severity=grave due to issues #7 and #9, although they are
> specific to plugins which are not enabled by default.)
> 
> AFAIK no CVE-ID have been published for these issues.  I'll request some
> later today unless someone beats me to it.

If you can request them that would be great, thank you.

Regards,
Salvatore



More information about the Pkg-roundcube-maintainers mailing list