PT-2026-29979 · Roundcube+1 · Roundcube Webmail+1

Y0Us

·

Published

2026-03-18

·

Updated

2026-05-25

·

CVE-2026-35540

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Roundcube Webmail versions 1.6.0 through 1.6.13
Description An issue exists in Roundcube Webmail where insufficient Cascading Style Sheets (CSS) sanitization in HTML email messages could lead to Server-Side Request Forgery (SSRF) or Information Disclosure. This can occur if stylesheet links point to local network hosts.
Recommendations Update Roundcube Webmail to version 1.6.14 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2026-06180
CVE-2026-35540
GHSA-VXG2-HHGR-37FX

Affected Products

Red Os
Roundcube Webmail