Updated roundcubemail packages fix security vulnerabilities
Publication date: 13 Aug 2026Modification date: 13 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-54432 , CVE-2026-54433 , CVE-2026-62641 , CVE-2026-62642 , CVE-2026-62643 , CVE-2026-62644
Description
Add basic validation for content proxied by the css proxy
Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and
fe80::/10 nets,
Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames
evading is_local_url() check
Fix remote content blocking bypass via unclosed url() in a FuncIRI
attribute
Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the
search_filter
Fix arbitrary Sieve script injection via a filter rule name bypassing
managesieve_disabled_actions
Fix RCE via cmd_learn driver of markasjunk plugin
Fix IMAP command injection via mail search and LITERAL+ byte-count
desynchronization
Fix password's modoboa driver leak of an authentication token to a
user-controlled host
Fix stored XSS in "Add to address book" action
Fix HTML/CSS sanitization bypass via SVG animate by attribute
References
- https://bugs.mageia.org/show_bug.cgi?id=36080
- https://github.com/roundcube/roundcubemail/releases/tag/1.7.3
- https://github.com/roundcube/roundcubemail/releases/tag/1.7.2
- https://www.cve.org/CVERecord?id=CVE-2026-54432
- https://www.cve.org/CVERecord?id=CVE-2026-54433
- https://www.cve.org/CVERecord?id=CVE-2026-62641
- https://www.cve.org/CVERecord?id=CVE-2026-62642
- https://www.cve.org/CVERecord?id=CVE-2026-62643
- https://www.cve.org/CVERecord?id=CVE-2026-62644
SRPMS
10/core
- roundcubemail-1.7.3-2.mga10