Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN830
_____________________________________________________________________

DATE                : 10/08/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Roundcube versions prior to
                                    1.6.18, 1.7.3.
 
=====================================================================
https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3
_____________________________________________________________________

Security updates 1.6.18 and 1.7.3 released

Published: 09 August 2026

    Tags: releases updates security 

We just published security updates to the 1.6 LTS and 1.7 versions
of Roundcube Webmail. They both contain fixes for recently reported
security vulnerabilities.


Security fixes

    Add basic validation for content proxied by the css proxy
    Fix SSRF bypass via specific local address URLs using 100.64.0.0/10
and fe80::/10 nets, reported by Dmytro Ivanenko
    Fix SSRF filter bypass via various forms of nip.io/sslip.io
hostnames evading is_local_url() check, reported by Milan Hoppe
    Fix remote content blocking bypass via unclosed url() in a FuncIRI
attribute, reported by Milan Hoppe
    Fix LDAP filter injection via unescaped %u/%fu/%d substitution into
the search_filter, reported by Milan Hoppe
    Fix arbitrary Sieve script injection via a filter rule name bypassing
managesieve_disabled_actions, reported by Milan Hoppe
    Fix RCE via cmd_learn driver of markasjunk plugin, reported by
nept1337
    Fix IMAP command injection via mail search and LITERAL+ byte-count
desynchronization, reported by Zach Hanley of Horizon3.ai
    Fix password’s modoboa driver leak of an authentication token to a
user-controlled host, reported by meifukun
    Fix stored XSS in “Add to address book” action, reported by Paulos
Yibelo from pwn.ai
    Fix HTML/CSS sanitization bypass via SVG animate by attribute,
reported by vectrain


See the full changelogs in the release notes on the Github download
pages for the updated versions 1.6.18 and 1.7.3.

We strongly recommend to update all productive installations of
Roundcube 1.6.x and 1.7.x with this new versions.


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




