PT-2026-89829 · Mageia · Roundcubemail

Published

2026-09-01

·

Updated

2026-09-01

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
  • Add basic validation for content proxied by the css proxy
  • Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets, reported by Dmytro Ivanenko
  • Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is local url() check, reported by Milan Hoppe
  • Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute, reported by Milan Hoppe
  • Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search filter, reported by Milan Hoppe
  • Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve disabled actions, reported by Milan Hoppe
  • Fix RCE via cmd learn driver of markasjunk plugin, reported by nept1337
  • Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization, reported by Zach Hanley of Horizon3.ai
  • Fix password’s modoboa driver leak of an authentication token to a user-controlled host, reported by meifukun
  • Fix stored XSS in “Add to address book” action, reported by Paulos Yibelo from pwn.ai
  • Fix HTML/CSS sanitization bypass via SVG animate by attribute, reported by vectrain
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

MGASA-2026-0358

Affected Products

Roundcubemail