[Pkg-roundcube-maintainers] Bug#1146838: roundcube: Multiple security vulnerabilities

Guilhem Moulin guilhem at debian.org
Sun Sep 6 10:31:01 BST 2026


Source: roundcube
Version: 1.6.18+dfsg-1
Control: found -1 1.6.18+dfsg-0+deb13u1
Control: found -1 1.6.5+dfsg-1+deb12u11
Severity: important
Tags: security upstream
X-Debbugs-Cc: Debian Security Team <team at security.debian.org>

Roundcube webmail upstream has just released 1.6.19 [0] which fixes
a new batch of security vulnerabilities:

  1. CSS declaration smuggling via un-encoded ampersand emission
     https://github.com/roundcube/roundcubemail/commit/8119eb061bffd6d967ee34e7bda21e20237fc1e0
  2. CSS property injection via body `background` attribute
     https://github.com/roundcube/roundcubemail/commit/030de9a4e58699a336f62868017ea5271128c52f
     Follow-up: https://github.com/roundcube/roundcubemail/commit/3092bd9fbe65b243cf419352ddd3e53e5086c6cc
     Follow-up: https://github.com/roundcube/roundcubemail/commit/2869de81c94dee300df4193276cce588f10350e1
     Follow-up: https://github.com/roundcube/roundcubemail/commit/29beae7282135a3cd59a3945bd33ee8f904d6217
  3. Email header injection via bare CR in the subject field
     https://github.com/roundcube/roundcubemail/commit/73d864e06cb26000a37ad57ae439842a85b6690e
  4. Email header injection via C-escape \r in the recipient display name
     https://github.com/roundcube/roundcubemail/commit/d1238ef1fb0d66a9bacf6b01926b911f70515071
  5. Email header injection via identity’s organization field
     https://github.com/roundcube/roundcubemail/commit/11e5c9be0369e3b76bfee2ae095f57532bae0f1f
  6. Zero-click stored XSS via TNEF MIME tag injection in the attachment URL
     https://github.com/roundcube/roundcubemail/commit/e4a0f82f4c648606de0867ee16b4a5f591ddbd69
     Follow-up: https://github.com/roundcube/roundcubemail/commit/7095e8d9de10d2f8bb90c3639c582edf8e371d5c
  7. XSS in the HTML editor using text/enriched part content
     https://github.com/roundcube/roundcubemail/commit/1381bf5d7e4c595560acf0228a2e68e471cefbd8
  8. Cross-user access in contact group membership (add/remove) in the SQL
     address book
     https://github.com/roundcube/roundcubemail/commit/19ba077a859b590bd886b437a6c8a3fdd8aa3952
  9. `is_local_url()` bypass via trailing-dot FQDN in stylesheet URL
     https://github.com/roundcube/roundcubemail/commit/9c4099bbff33062c8ab6e09d9b71e59dde295408
  10. Remote content blocking bypass via CSS escapes in FuncIRI attributes
      https://github.com/roundcube/roundcubemail/commit/9aa2b3f13c3707ac24aee9899dd4ab693ee1e471
  11. Remote-content blocker bypass via SVG SMIL src animation
      https://github.com/roundcube/roundcubemail/commit/2bed9eeb5707636b8e5b915ae18d4d06b3971f31
  12. SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4
      addresses
      https://github.com/roundcube/roundcubemail/commit/05cc67c6bc501e2d818436dec571f9712f16ea61

AFAIK no CVE-ID have been published for these issues.  I'm currently
traveling but will request some next week unless someone beats me to it.
-- 
Guilhem.

[0] https://roundcube.net/news/2026/09/06/security-updates-1.6.19-and-1.7.4
    https://github.com/roundcube/roundcubemail/releases/tag/1.6.19
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-roundcube-maintainers/attachments/20260906/2860a87c/attachment.sig>


More information about the Pkg-roundcube-maintainers mailing list