PT-2026-80575 · Mageia · Roundcubemail

Published

2026-08-13

·

Updated

2026-08-13

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Add basic validation for content proxied by the css proxy Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets, Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is local url() check Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search filter Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve disabled actions Fix RCE via cmd learn driver of markasjunk plugin Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization Fix password's modoboa driver leak of an authentication token to a user-controlled host Fix stored XSS in "Add to address book" action Fix HTML/CSS sanitization bypass via SVG animate by attribute
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

MGASA-2026-0333

Affected Products

Roundcubemail