CVE-2026-75006

NameCVE-2026-75006
DescriptionIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4760-1, DSA-6479-1
Debian Bugs1144059

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
roundcube (PTS)bullseye1.4.15+dfsg.1-1+deb11u4vulnerable
bullseye (security)1.4.15+dfsg.1-1+deb11u11fixed
bookworm1.6.5+dfsg-1+deb12u9vulnerable
bookworm (security)1.6.5+dfsg-1+deb12u11fixed
trixie1.6.16+dfsg-0+deb13u1vulnerable
trixie (security)1.6.18+dfsg-0+deb13u1fixed
forky, sid1.6.18+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
roundcubesourcebullseye1.4.15+dfsg.1-1+deb11u11DLA-4760-1
roundcubesourcebookworm1.6.5+dfsg-1+deb12u11DLA-4760-1
roundcubesourcetrixie1.6.18+dfsg-0+deb13u1DSA-6479-1
roundcubesource(unstable)1.6.18+dfsg-11144059

Notes

Fixed by: https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223 (1.6.18)
Fixed by: https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9 (1.6.18)

Search for package or bug name: Reporting problems