PT-2026-80575 · Mageia · Roundcubemail
Publicado
2026-08-13
·
Atualizado
2026-08-13
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Add basic validation for content proxied by the css proxy
Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and
fe80::/10 nets,
Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames
evading is local url() check
Fix remote content blocking bypass via unclosed url() in a FuncIRI
attribute
Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the
search filter
Fix arbitrary Sieve script injection via a filter rule name bypassing
managesieve disabled actions
Fix RCE via cmd learn driver of markasjunk plugin
Fix IMAP command injection via mail search and LITERAL+ byte-count
desynchronization
Fix password's modoboa driver leak of an authentication token to a
user-controlled host
Fix stored XSS in "Add to address book" action
Fix HTML/CSS sanitization bypass via SVG animate by attribute
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Roundcubemail