PT-2026-29979 · Roundcube+1 · Roundcube Webmail+1
Y0Us
·
Published
2026-03-18
·
Updated
2026-05-25
·
CVE-2026-35540
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Roundcube Webmail versions 1.6.0 through 1.6.13
Description
An issue exists in Roundcube Webmail where insufficient Cascading Style Sheets (CSS) sanitization in HTML email messages could lead to Server-Side Request Forgery (SSRF) or Information Disclosure. This can occur if stylesheet links point to local network hosts.
Recommendations
Update Roundcube Webmail to version 1.6.14 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Os
Roundcube Webmail