[Pkg-roundcube-maintainers] Bug#1146838: roundcube: Multiple security vulnerabilities
Guilhem Moulin
guilhem at debian.org
Sun Sep 6 10:31:01 BST 2026
Source: roundcube
Version: 1.6.18+dfsg-1
Control: found -1 1.6.18+dfsg-0+deb13u1
Control: found -1 1.6.5+dfsg-1+deb12u11
Severity: important
Tags: security upstream
X-Debbugs-Cc: Debian Security Team <team at security.debian.org>
Roundcube webmail upstream has just released 1.6.19 [0] which fixes
a new batch of security vulnerabilities:
1. CSS declaration smuggling via un-encoded ampersand emission
https://github.com/roundcube/roundcubemail/commit/8119eb061bffd6d967ee34e7bda21e20237fc1e0
2. CSS property injection via body `background` attribute
https://github.com/roundcube/roundcubemail/commit/030de9a4e58699a336f62868017ea5271128c52f
Follow-up: https://github.com/roundcube/roundcubemail/commit/3092bd9fbe65b243cf419352ddd3e53e5086c6cc
Follow-up: https://github.com/roundcube/roundcubemail/commit/2869de81c94dee300df4193276cce588f10350e1
Follow-up: https://github.com/roundcube/roundcubemail/commit/29beae7282135a3cd59a3945bd33ee8f904d6217
3. Email header injection via bare CR in the subject field
https://github.com/roundcube/roundcubemail/commit/73d864e06cb26000a37ad57ae439842a85b6690e
4. Email header injection via C-escape \r in the recipient display name
https://github.com/roundcube/roundcubemail/commit/d1238ef1fb0d66a9bacf6b01926b911f70515071
5. Email header injection via identity’s organization field
https://github.com/roundcube/roundcubemail/commit/11e5c9be0369e3b76bfee2ae095f57532bae0f1f
6. Zero-click stored XSS via TNEF MIME tag injection in the attachment URL
https://github.com/roundcube/roundcubemail/commit/e4a0f82f4c648606de0867ee16b4a5f591ddbd69
Follow-up: https://github.com/roundcube/roundcubemail/commit/7095e8d9de10d2f8bb90c3639c582edf8e371d5c
7. XSS in the HTML editor using text/enriched part content
https://github.com/roundcube/roundcubemail/commit/1381bf5d7e4c595560acf0228a2e68e471cefbd8
8. Cross-user access in contact group membership (add/remove) in the SQL
address book
https://github.com/roundcube/roundcubemail/commit/19ba077a859b590bd886b437a6c8a3fdd8aa3952
9. `is_local_url()` bypass via trailing-dot FQDN in stylesheet URL
https://github.com/roundcube/roundcubemail/commit/9c4099bbff33062c8ab6e09d9b71e59dde295408
10. Remote content blocking bypass via CSS escapes in FuncIRI attributes
https://github.com/roundcube/roundcubemail/commit/9aa2b3f13c3707ac24aee9899dd4ab693ee1e471
11. Remote-content blocker bypass via SVG SMIL src animation
https://github.com/roundcube/roundcubemail/commit/2bed9eeb5707636b8e5b915ae18d4d06b3971f31
12. SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4
addresses
https://github.com/roundcube/roundcubemail/commit/05cc67c6bc501e2d818436dec571f9712f16ea61
AFAIK no CVE-ID have been published for these issues. I'm currently
traveling but will request some next week unless someone beats me to it.
--
Guilhem.
[0] https://roundcube.net/news/2026/09/06/security-updates-1.6.19-and-1.7.4
https://github.com/roundcube/roundcubemail/releases/tag/1.6.19
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-roundcube-maintainers/attachments/20260906/2860a87c/attachment.sig>
More information about the Pkg-roundcube-maintainers
mailing list