TEMP-1146838-6627BB

NameTEMP-1146838-6627BB
DescriptionSSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses
SourceAutomatically generated temporary name. Not for external reference.
Debian Bugs1146838

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
roundcube (PTS)bookworm1.6.5+dfsg-1+deb12u9fixed
bookworm (security)1.6.5+dfsg-1+deb12u11fixed
trixie1.6.16+dfsg-0+deb13u1fixed
trixie (security)1.6.18+dfsg-0+deb13u1fixed
forky1.6.18+dfsg-1fixed
sid1.6.19+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
roundcubesourcebookworm1.6.5+dfsg-1+deb12u9
roundcubesourcetrixie1.6.16+dfsg-0+deb13u1
roundcubesource(unstable)1.6.16+dfsg-11146838

Notes

Fixed by: https://github.com/roundcube/roundcubemail/commit/05cc67c6bc501e2d818436dec571f9712f16ea61 (1.6.19)
The updated Debian patch (Avoid-dependency-on-new-package-mlocati-ip-lib.patch)
to address CVE-2026-48843 solves this problem as well by properly handle
non-quad/non-decimal mapped v4 addresses.

Search for package or bug name: Reporting problems