MGASA-2026-0194

Source
https://advisories.mageia.org/MGASA-2026-0194.html
Import Source
https://advisories.mageia.org/MGASA-2026-0194.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0194
Upstream
  • CVE-2026-48842
  • CVE-2026-48843
  • CVE-2026-48844
  • CVE-2026-48845
  • CVE-2026-48846
  • CVE-2026-48847
  • CVE-2026-48848
  • CVE-2026-48849
Published
2026-06-11T01:40:05Z
Modified
2026-06-11T01:45:04.730038940Z
Summary
Updated roundcubemail packages fix security vulnerabilities
Details

Multiple security vulnerabilities were discovered in RoundCube Webmail, which could result in cross-site scripting, SQL injection, SSRF bypass, information disclosure, denial of service or code injection.

References
Credits

Affected packages

Mageia:9 / roundcubemail

Package

Name
roundcubemail
Purl
pkg:rpm/mageia/roundcubemail?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.16-1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0194.json"