Bug#1144059: roundcube: Multiple security vulnerabilities

Guilhem Moulin <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <aoMQ2fbSVSGnPmM5__5310.42400268547$1786974556$gmane$org@debian.org>
On Mon, 10 Aug 2026 at 14:30:56 +0200, Guilhem Moulin wrote:
> 1. Content proxied by the css proxy is not validated validation
>  https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b

CVE-2026-74998 was assigned for this issue.

> 2. SSRF bypass via specific local address URLs using 100.64.0.0/10 and
>  fe80::/10 subnets
>  https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223
> 3. SSRF filter bypass via various forms of nip.io/sslip.io hostnames
>  evading is_local_url() check
>  https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9

CVE-2026-75006 was assigned for these issues (I requested a single CVE
ID since the impact and code path are the same).

> 4. Remote content blocking bypass via unclosed url() in a FuncIRI
>  attribute
>  https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b

CVE-2026-75003 was assigned for this issue.

> 5. LDAP filter injection via unescaped %u/%fu/%d substitution into the
>  `search_filter`
>  https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540

CVE-2026-75007 was assigned for this issue.

> 6. Arbitrary sieve script injection via a filter rule name bypassing
>  `managesieve_disabled_actions`
>  https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e

CVE-2026-75004 was assigned for this issue.

> 7. RCE in the `cmd_learn` driver of markasjunk plugin
>  https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd
>  Follow-up: https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a

CVE-2026-74997 was assigned for this issue.

> 8. IMAP command injection via mail search and LITERAL+ byte-count
>  desynchronization
>  https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea

CVE-2026-75002 was assigned for this issue.

> 9. The modoboa driver of the passwd plugin leaks an authentication
>  token to a user-controlled host
>  https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c

CVE-2026-75010 was assigned for this issue.

> 10. Stored XSS in “Add to address book” action
>   https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8

CVE-2026-74999 was assigned for this issue.

> 11. HTML/CSS sanitization bypass via SVG animate `by` attribute
>   https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f

CVE-2026-75000 was assigned for this issue.


I will prepare a debdiff for trixie-security shortly.

-- 
Guilhem.
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmqDENkACgkQ05pJnDwh
pVLk/xAAnsjNLb6oy0x8lFV6CYwRGuaj0tpgRQB+diePp2Lu88at8XQv5HRrgsJd
9AU/3lw/M5CK1l2FYJcpZF6AiYC6v/qypJwM5+/HKSj0UO8PCAMOTkm0PWzoUWJ+
BWP1Hzqx22Tzy8f4uKGfY3hBSOdzllPDidPBFU+0FnVGXLM3b85M03smZZ6Lr7zN
fBT67FSuDK7JbPcMFn3egDwWbiMYo6Mx8WC7qvnIxOgIVyjHnoVd1tRO4xlck94P
4BaXx6zXa8aghqv2mp5Vk382k8DiCedLbTT4xseug4Gw43TIEjkXAuUN6QBWrrT/
X/8Se7LxMOCfjzFXjut4g9qqCKX1ap0mFzd//vHCxJsB1buq+RI0kEINFMJLHUvB
1TxtwZAzvP9r767iy2fbolr0DEYIvRsOW1MyuVbAz6YQlN3N5V8bntBAuiPZLA7V
dIJq6T5ED5/YsJQI8z+o09Z3hIwTWC5cmnfkGtLTNrPgSAFKjhrCZ8M6GAP3y+o4
MbW7cHTleyDvw92VI/T2zj/6kAOWlN/Wxx43FIcdLM0CAKQ/4OAfLc+LZbM+WBVC
iVs90fAhFMKXVcPExx/M036M61YyAxHrPwDSIOyDwyIQB4vWfPK7ykt/9IyIKM5/
A8g6FfUpGdAcBUeF7sgP+Rn6AGvCtocVa43dB94lwqTd1b6DEAE=
=i2S6
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.