MGASA-2026-0358

Source
https://advisories.mageia.org/MGASA-2026-0358.html
Import Source
https://advisories.mageia.org/MGASA-2026-0358.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0358
Published
2026-09-01T03:06:53Z
Modified
2026-09-01T03:15:03.614604249Z
Summary
Updated roundcubemail packages fix security vulnerabilities
Details
  • Add basic validation for content proxied by the css proxy
  • Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets, reported by Dmytro Ivanenko
  • Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading islocalurl() check, reported by Milan Hoppe
  • Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute, reported by Milan Hoppe
  • Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter, reported by Milan Hoppe
  • Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions, reported by Milan Hoppe
  • Fix RCE via cmd_learn driver of markasjunk plugin, reported by nept1337
  • Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization, reported by Zach Hanley of Horizon3.ai
  • Fix password’s modoboa driver leak of an authentication token to a user-controlled host, reported by meifukun
  • Fix stored XSS in “Add to address book” action, reported by Paulos Yibelo from pwn.ai
  • Fix HTML/CSS sanitization bypass via SVG animate by attribute, reported by vectrain
References
Credits

Affected packages

Mageia:9 / roundcubemail

Package

Name
roundcubemail
Purl
pkg:rpm/mageia/roundcubemail?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.18-1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0358.json"