On Mon, 10 Aug 2026 at 14:30:56 +0200, Guilhem Moulin wrote:
> 1. Content proxied by the css proxy is not validated validation
>  
> https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b

CVE-2026-74998 was assigned for this issue.

> 2. SSRF bypass via specific local address URLs using 100.64.0.0/10 and
>  fe80::/10 subnets
>  
> https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223
> 3. SSRF filter bypass via various forms of nip.io/sslip.io hostnames
>  evading is_local_url() check
>  
> https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9

CVE-2026-75006 was assigned for these issues (I requested a single CVE
ID since the impact and code path are the same).

> 4. Remote content blocking bypass via unclosed url() in a FuncIRI
>  attribute
>  
> https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b

CVE-2026-75003 was assigned for this issue.

> 5. LDAP filter injection via unescaped %u/%fu/%d substitution into the
>  `search_filter`
>  
> https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540

CVE-2026-75007 was assigned for this issue.

> 6. Arbitrary sieve script injection via a filter rule name bypassing
>  `managesieve_disabled_actions`
>  
> https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e

CVE-2026-75004 was assigned for this issue.

> 7. RCE in the `cmd_learn` driver of markasjunk plugin
>  
> https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd
>  Follow-up: 
> https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a

CVE-2026-74997 was assigned for this issue.

> 8. IMAP command injection via mail search and LITERAL+ byte-count
>  desynchronization
>  
> https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea

CVE-2026-75002 was assigned for this issue.

> 9. The modoboa driver of the passwd plugin leaks an authentication
>  token to a user-controlled host
>  
> https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c

CVE-2026-75010 was assigned for this issue.

> 10. Stored XSS in “Add to address book” action
>   
> https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8

CVE-2026-74999 was assigned for this issue.

> 11. HTML/CSS sanitization bypass via SVG animate `by` attribute
>   
> https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f

CVE-2026-75000 was assigned for this issue.


I will prepare a debdiff for trixie-security shortly.

-- 
Guilhem.

Attachment: signature.asc
Description: PGP signature

Reply via email to