Updated roundcubemail packages fix security vulnerabilities
Publication date: 01 Sep 2026Modification date: 01 Sep 2026
Type: security
Affected Mageia releases : 9
Description
* Add basic validation for content proxied by the css proxy
* Fix SSRF bypass via specific local address URLs using 100.64.0.0/10
and fe80::/10 nets, reported by Dmytro Ivanenko
* Fix SSRF filter bypass via various forms of nip.io/sslip.io
hostnames evading is_local_url() check, reported by Milan Hoppe
* Fix remote content blocking bypass via unclosed url() in a FuncIRI
attribute, reported by Milan Hoppe
* Fix LDAP filter injection via unescaped %u/%fu/%d substitution into
the `search_filter`, reported by Milan Hoppe
* Fix arbitrary Sieve script injection via a filter rule name
bypassing `managesieve_disabled_actions`, reported by Milan Hoppe
* Fix RCE via cmd_learn driver of markasjunk plugin, reported by
nept1337
* Fix IMAP command injection via mail search and LITERAL+ byte-count
desynchronization, reported by Zach Hanley of Horizon3.ai
* Fix password’s modoboa driver leak of an authentication token to a
user-controlled host, reported by
[meifukun](https://github.com/meifukun)
* Fix stored XSS in “Add to address book” action, reported by Paulos
Yibelo from pwn.ai
* Fix HTML/CSS sanitization bypass via SVG animate `by` attribute,
reported by vectrain
References
SRPMS
9/core
- roundcubemail-1.6.18-1.mga9