gpp_maybe
Security update for roundcubemail
openSUSE-2026-183
This update for roundcubemail fixes the following issues: Update to 1.6.16 - Fix potential too long value in IMAP ID command (#10136) - CVE-2026-48849: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [boo#1266337] - CVE-2026-48848: Fix CSS injection bypass in HTML sanitizer via SVG <animate attributeName="style"> [boo#1266336] - CVE-2026-48842: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [boo#1266329] - CVE-2026-48843: Fix SSRF bypass via specific local address URLs [boo#1266331] - CVE-2026-48846: Fix bypass of remote image blocking via CSS var() [boo#1266334] - CVE-2026-48845: Fix local/private URL fetch bypass when remote resources were not allowed [boo#1266333] - CVE-2026-48847: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [boo#1266335] - CVE-2026-48844: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option [boo#1266332]
-
Release DateJun 2 2026
-
ReferencesBugzilla: 1266335, 1266334, 1266332, 1266329, 1266333, 1266337, 1266331, 1266336
CVEs: CVE-2026-48844, CVE-2026-48842, CVE-2026-48845, CVE-2026-48847, CVE-2026-48846, CVE-2026-48848, CVE-2026-48843, CVE-2026-48849 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Package Hub 15.7 aarch64
-
Packages
SUSE Package Hub 15.7 x86_64
-
Packages
SUSE Package Hub 15.7 s390x
-
Packages
SUSE Package Hub 15.7 ppc64le
-
Packages