PT-2026-80575 · Mageia · Roundcubemail
Published
2026-08-13
·
Updated
2026-08-13
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Add basic validation for content proxied by the css proxy
Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and
fe80::/10 nets,
Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames
evading is local url() check
Fix remote content blocking bypass via unclosed url() in a FuncIRI
attribute
Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the
search filter
Fix arbitrary Sieve script injection via a filter rule name bypassing
managesieve disabled actions
Fix RCE via cmd learn driver of markasjunk plugin
Fix IMAP command injection via mail search and LITERAL+ byte-count
desynchronization
Fix password's modoboa driver leak of an authentication token to a
user-controlled host
Fix stored XSS in "Add to address book" action
Fix HTML/CSS sanitization bypass via SVG animate by attribute
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Roundcubemail