Mageia alert MGASA-2026-0358 (roundcubemail)
| From: | Mageia Updates <updates-announce@ml.mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2026-0358: Updated roundcubemail packages fix security vulnerabilities | |
| Date: | Tue, 01 Sep 2026 05:07:44 +0200 | |
| Message-ID: | <20260901030744.5B2019FECF@duvel.mageia.org> | |
| Archive-link: | Article |
MGASA-2026-0358 - Updated roundcubemail packages fix security vulnerabilities Publication date: 01 Sep 2026 URL: https://advisories.mageia.org/MGASA-2026-0358.html Type: security Affected Mageia releases: 9 Description: * Add basic validation for content proxied by the css proxy * Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets, reported by Dmytro Ivanenko * Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check, reported by Milan Hoppe * Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute, reported by Milan Hoppe * Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the `search_filter`, reported by Milan Hoppe * Fix arbitrary Sieve script injection via a filter rule name bypassing `managesieve_disabled_actions`, reported by Milan Hoppe * Fix RCE via cmd_learn driver of markasjunk plugin, reported by nept1337 * Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization, reported by Zach Hanley of Horizon3.ai * Fix password’s modoboa driver leak of an authentication token to a user-controlled host, reported by [meifukun](https://github.com/meifukun) * Fix stored XSS in “Add to address book” action, reported by Paulos Yibelo from pwn.ai * Fix HTML/CSS sanitization bypass via SVG animate `by` attribute, reported by vectrain References: - https://bugs.mageia.org/show_bug.cgi?id=36135 - https://www.openwall.com/lists/oss-security/2026/08/10/2 - https://github.com/roundcube/roundcubemail/releases/tag/1... SRPMS: - 9/core/roundcubemail-1.6.18-1.mga9
