openSUSE-SU-2026:20852-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20852-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20852-1
Upstream
CVE (8)
Related
Published
2026-05-31T10:25:53Z
Modified
2026-06-02T08:45:08Z
Summary
Security update for roundcubemail
Details

This update for roundcubemail fixes the following issues:

Changes in roundcubemail:

  • update to 1.6.16
    • Fix potential too long value in IMAP ID command (#10136)
    • Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [CVE-2026-48849] [bsc#1266337]
    • Security: Fix CSS injection bypass in HTML sanitizer via SVG 'animate attributeName="style"' [CVE-2026-48848] [bsc#1266336]
    • Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [CVE-2026-48842] [bsc#1266329]
    • Security: Fix SSRF bypass via specific local address URLs [CVE-2026-48843] [bsc#1266331]
    • Security: Fix bypass of remote image blocking via CSS var() [CVE-2026-48846] [bsc#1266334]
    • Security: Fix local/private URL fetch bypass when remote resources were not allowed [CVE-2026-48845] [bsc#1266333]
    • Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [CVE-2026-48847] [bsc#1266335]
    • Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option [CVE-2026-48844] [bsc#1266332]
References

Affected packages