Your message dated Mon, 10 Aug 2026 22:05:04 +0000
with message-id <[email protected]>
and subject line Bug#1144059: fixed in roundcube 1.6.18+dfsg-1
has caused the Debian Bug report #1144059,
regarding roundcube: Multiple security vulnerabilities
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1144059: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144059
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: roundcube
Version: 1.6.17+dfsg-1
Control: found -1 1.6.17+dfsg-0+deb13u1
Control: found -1 1.6.5+dfsg-1+deb12u10
Control: found -1 1.4.15+dfsg.1-1+deb11u10
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: Debian Security Team <[email protected]>
Roundcube webmail upstream has recently released 1.6.17 [0] which fixes
the following security vulnerabilities:
1. Content proxied by the css proxy is not validated validation
https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b
2. SSRF bypass via specific local address URLs using 100.64.0.0/10 and
fe80::/10 subnets
https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223
3. SSRF filter bypass via various forms of nip.io/sslip.io hostnames
evading is_local_url() check
https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9
4. Remote content blocking bypass via unclosed url() in a FuncIRI
attribute
https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b
5. LDAP filter injection via unescaped %u/%fu/%d substitution into the
`search_filter`
https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540
6. Arbitrary sieve script injection via a filter rule name bypassing
`managesieve_disabled_actions`
https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e
7. RCE in the `cmd_learn` driver of markasjunk plugin
https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd
Follow-up:
https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a
8. IMAP command injection via mail search and LITERAL+ byte-count
desynchronization
https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea
9. The modoboa driver of the passwd plugin leaks an authentication
token to a user-controlled host
https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c
10. Stored XSS in “Add to address book” action
https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8
11. HTML/CSS sanitization bypass via SVG animate `by` attribute
https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f
(Using severity=grave due to issues #7 and #9, although they are
specific to plugins which are not enabled by default.)
AFAIK no CVE-ID have been published for these issues. I'll request some
later today unless someone beats me to it.
--
Guilhem.
[0] https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3
signature.asc
Description: PGP signature
--- End Message ---
--- Begin Message ---
Source: roundcube
Source-Version: 1.6.18+dfsg-1
Done: Guilhem Moulin <[email protected]>
We believe that the bug you reported is fixed in the latest version of
roundcube, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Guilhem Moulin <[email protected]> (supplier of updated roundcube package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 10 Aug 2026 15:15:16 +0200
Source: roundcube
Architecture: source
Version: 1.6.18+dfsg-1
Distribution: unstable
Urgency: high
Maintainer: Debian Roundcube Maintainers
<[email protected]>
Changed-By: Guilhem Moulin <[email protected]>
Closes: 1144059
Changes:
roundcube (1.6.18+dfsg-1) unstable; urgency=high
.
* New upstream security and bugfix release (closes: #1144059).
+ Content proxied by the css proxy is not validated validation.
+ SSRF bypass via specific local address URLs using 100.64.0.0/10 and
fe80::/10 subnets.
+ SSRF filter bypass via various forms of nip.io/sslip.io hostnames
evading `is_local_url()` check.
+ Remote content blocking bypass via unclosed `url()` in a FuncIRI
attribute.
+ LDAP filter injection via unescaped %u/%fu/%d substitution into the
`search_filter`.
+ Arbitrary sieve script injection via a filter rule name bypassing
`managesieve_disabled_actions`.
+ RCE in the `cmd_learn` driver of markasjunk plugin.
+ IMAP command injection via mail search and LITERAL+ byte-count
desynchronization.
+ The modoboa driver of the passwd plugin leaks an authentication
token to a user-controlled host.
+ Stored XSS in "Add to address book" action.
+ HTML/CSS sanitization bypass via SVG animate `by` attribute.
* Refresh d/patches.
* Cherry-pick follow-up change to fix PHP warning in markasjunk's
cmd_learn.php.
Checksums-Sha1:
7baebfb91ba8cd774b09a1bd9eba8aa358da1c5e 3845 roundcube_1.6.18+dfsg-1.dsc
d1f446017c4ecc7d79a0ea6b465feb3fbee7b9c7 126948
roundcube_1.6.18+dfsg.orig-tinymce-langs.tar.xz
af0bba30402c4c02beaca3ae96ac6aa12a4a6da6 1928640
roundcube_1.6.18+dfsg.orig-tinymce.tar.xz
2b80f406956df4da1213893520778b94814aacd0 2907948
roundcube_1.6.18+dfsg.orig.tar.xz
5ac234f7d61dc9868667328b0a4c4617739a8ebb 159932
roundcube_1.6.18+dfsg-1.debian.tar.xz
2444dd3097df882acdd772fdca20517a664e9ce8 6267
roundcube_1.6.18+dfsg-1_source.buildinfo
Checksums-Sha256:
23b49565b6327af40aad18bfe286f31846ea242b356a7ab420e3c26eb8959ae3 3845
roundcube_1.6.18+dfsg-1.dsc
f009f44443e465cd7a06a758cb878402868f61b47762bf247f572fd2b3fd1bfb 126948
roundcube_1.6.18+dfsg.orig-tinymce-langs.tar.xz
518547256094a0214580e18b22693cc63d54dd059d8a8116a967898c854a7acb 1928640
roundcube_1.6.18+dfsg.orig-tinymce.tar.xz
b413364d67014758eb4a4b87adc2a0f465e0a0bedf23d644d61955280f1df900 2907948
roundcube_1.6.18+dfsg.orig.tar.xz
1c542e61291d3fa88aa4f3012eecd69dbb549291572e2d97d270bf62ea85ce84 159932
roundcube_1.6.18+dfsg-1.debian.tar.xz
8f31c303e98a4e46b1cf2528489ad219003b173f9a74fa5bd094de19604eac0c 6267
roundcube_1.6.18+dfsg-1_source.buildinfo
Files:
cc4f51b8b3dd63b2d0dd5af04c67b65d 3845 web optional roundcube_1.6.18+dfsg-1.dsc
6d1099a82016ca3d45dbba79295f6e30 126948 web optional
roundcube_1.6.18+dfsg.orig-tinymce-langs.tar.xz
49949888729c8204636bc14cffcfa003 1928640 web optional
roundcube_1.6.18+dfsg.orig-tinymce.tar.xz
8e988bb1541cf388be0bd2630e01dc90 2907948 web optional
roundcube_1.6.18+dfsg.orig.tar.xz
37bae46e8fd6d258d674b855336ceea8 159932 web optional
roundcube_1.6.18+dfsg-1.debian.tar.xz
6c177af0cd190b55038131044b936f6d 6267 web optional
roundcube_1.6.18+dfsg-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmp6RvgACgkQ05pJnDwh
pVK7GQ/8DWHdVZIVwciMppsNtzrrBlT14Hhq4XzHJRrFYPO9gGjl7NfU3kubRBqD
C3OqRAznGR5jWJEGNODdKqnE/gG7wd3fp5D5wlljpsCtp4knjuqV0JWqf95WI3f1
qyv4MI8Lo2RDCQ0+zfUd1chnHFj8sX8jJKBYSyUVGA2ZuTUnVBvvLHavzz79lRGY
cgp+CSkYMHLDSgUF6YjwtHf40myCWhtIPCj+HoTIc7jLXXT7ugmLeEXB0wN/SRmK
wJhxJtBJ4aeiLlwtAsv1aLAelpreyHw+9506wg5hLSXaTZOHAWxTzw4LZkOX1KSV
CHwO+3fECnp96ieJR3LH7m9GRizgVCwOKg+N1DQdwTmutOT+NP01YE/Tl5P0LBFv
XZRvS5/zFxz1T9SbNGCMJZLIhQb+6i5kl5c+XYHYuHxGLovbLal3rMg+TwyZi2Au
wijKc9BGVUVX3NpHrvYywnbIsu6OAFNmsBGIK/Ml1Mx51rxojhCSNo/oHkoTSUtP
Wlesnod5vyRT08sOLvC2F1Fo2hCbKbR3fQKzIBHomk+gJ4KSMB9tDvWpYOls8LD+
ObD5racM2b8OcfzpwFHvplzCVOYKbyBxJXSRa5LD/c/v94+2bueG2KOLSLvRmhr4
BovKQKTKzdQEUJnBCl5ytWMPFvYIH+DfBqd2tyPydI7Z3tM7FEs=
=Z2b7
-----END PGP SIGNATURE-----
pgpVx8lrqqNBy.pgp
Description: PGP signature
--- End Message ---