[Pkg-roundcube-maintainers] Bug#1146838: roundcube: Multiple security vulnerabilities

Salvatore Bonaccorso carnil at debian.org
Sun Sep 6 13:54:22 BST 2026


Hi Guilhem,

On Sun, Sep 06, 2026 at 12:20:17PM +0200, Guilhem Moulin wrote:
> On Sun, 06 Sep 2026 at 11:31:01 +0200, Guilhem Moulin wrote:
> > 12. SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4
> >   addresses
> >   https://github.com/roundcube/roundcubemail/commit/05cc67c6bc501e2d818436dec571f9712f16ea61
> 
> The Debian package (in all suites) is not affected by that one, because
> my patch to avoid the mlocati/ip-lib dependency already handles these
> addresses.

That is every updated version which contain the
Avoid-dependency-on-new-package-mlocati-ip-lib.patch patch right?

Regards,
Salvatore



More information about the Pkg-roundcube-maintainers mailing list