stable

roundcubemail-1.6.16-1.fc43

FEDORA-2026-07ee097ffe created by remi 3 months ago for Fedora 43

Release 1.6.16

  • Fix potential too long value in IMAP ID command (#10136)
  • Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog
  • Security: Fix CSS injection bypass in HTML sanitizer via SVG <animate attributeName="style">
  • Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass
  • Security: Fix SSRF bypass via specific local address URLs
  • Security: Fix bypass of remote image blocking via CSS var()
  • Security: Fix local/private URL fetch bypass when remote resources were not allowed
  • Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass
  • Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-07ee097ffe

This update has been submitted for testing by remi.

3 months ago

This update's test gating status has been changed to 'ignored'.

3 months ago

This update has been pushed to testing.

3 months ago

remi edited this update.

3 months ago

This update has been submitted for stable by bodhi.

2 months ago

This update has been pushed to stable.

2 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
3 months ago
in testing
3 months ago
in stable
2 months ago
modified
3 months ago
approved
2 months ago
BZ#2481615 CVE-2026-48842 roundcubemail: pre-auth SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass [fedora-all]
0
0
BZ#2481617 CVE-2026-48844 roundcubemail: code injection via insecure LDAP autovalues option [fedora-all]
0
0
BZ#2481619 CVE-2026-48843 roundcubemail: information disclosure and Server-Side Request Forgery via insufficient CSS sanitization [fedora-all]
0
0
BZ#2481622 CVE-2026-48845 roundcubemail: privilege escalation via remote image blocking bypass [fedora-all]
0
0
BZ#2481624 CVE-2026-48848 roundcubemail: CSS injection via an SVG document that has an animate element with the attributeName attribute [fedora-all]
0
0
BZ#2481626 CVE-2026-48847 roundcubemail: arbitrary file deletion via redis/memcache session poisoning bypass [fedora-all]
0
0
BZ#2481628 CVE-2026-48846 roundcubemail: remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message [fedora-all]
0
0
BZ#2481629 CVE-2026-48849 roundcubemail: XSS via unsanitized subject field in the draft restored value [fedora-all]
0
0

Automated Test Results