[Pkg-roundcube-maintainers] Bug#1137507: roundcube: Multiple security vulnerabilities

Guilhem Moulin guilhem at debian.org
Sun May 24 12:12:24 BST 2026


Source: roundcube
Version: 1.6.15+dfsg-1
Control: found -1 1.6.15+dfsg-0+deb13u1
Control: found -1 1.6.5+dfsg-1+deb12u8
Control: found -1 1.4.15+dfsg.1-1+deb11u8
Severity: grave
Justification: user security hole
Tags: security upstream
X-Debbugs-Cc: Debian Security Team <team at security.debian.org>

Roundcube webmail upstream has recently released 1.6.16 [0] which fixes
the following security vulnerabilities:

  1. Stored XSS/HTML/CSS injection in subject field of the draft restore
     dialog.
  2. CSS injection bypass in HTML sanitizer via SVG <animate
     attributeName="style">.
  3. Pre-auth SQL injection in virtuser_query plugin via preg_replace
     backslash escape bypass.
  4. SSRF bypass via specific local address URLs.
  5. Local/private URL fetch bypass when remote resources were not
     allowed.
  6. Bypass of remote image blocking via CSS var().
  7. Pre-auth arbitrary file delete via redis/memcache session poisoning
     bypass.
  8. Code injection vulnerability via code evaluation support in LDAP
     autovalues option.  Code evaluation support has now been removed.

AFAIK no CVE-ID have been published for these issues.  I'll requested
some later today unless someone beats me to it.
-- 
Guilhem.

[0] https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-roundcube-maintainers/attachments/20260524/be170704/attachment.sig>


More information about the Pkg-roundcube-maintainers mailing list