Advisories » MGASA-2026-0358

Updated roundcubemail packages fix security vulnerabilities

Publication date: 01 Sep 2026
Modification date: 01 Sep 2026
Type: security
Affected Mageia releases : 9

Description

* Add basic validation for content proxied by the css proxy
* Fix SSRF bypass via specific local address URLs using 100.64.0.0/10
  and fe80::/10 nets, reported by Dmytro Ivanenko
* Fix SSRF filter bypass via various forms of nip.io/sslip.io
  hostnames evading is_local_url() check, reported by Milan Hoppe
* Fix remote content blocking bypass via unclosed url() in a FuncIRI
  attribute, reported by Milan Hoppe
* Fix LDAP filter injection via unescaped %u/%fu/%d substitution into
  the `search_filter`, reported by Milan Hoppe
* Fix arbitrary Sieve script injection via a filter rule name
  bypassing `managesieve_disabled_actions`, reported by Milan Hoppe
* Fix RCE via cmd_learn driver of markasjunk plugin, reported by
  nept1337
* Fix IMAP command injection via mail search and LITERAL+ byte-count
  desynchronization, reported by Zach Hanley of Horizon3.ai
* Fix password’s modoboa driver leak of an authentication token to a
  user-controlled host, reported by
  [meifukun](https://github.com/meifukun)
* Fix stored XSS in “Add to address book” action, reported by Paulos
  Yibelo from pwn.ai
* Fix HTML/CSS sanitization bypass via SVG animate `by` attribute,
  reported by vectrain
                

References

SRPMS

9/core