Güvenlik Danışarlıklarına Dön

Roundcube 1.7.2 / 1.6.17 CVE

Roundcube 1.7.2 and 1.6.17 (published 5 July 2026) fix two security vulnerabilities: a stored XSS via an unescaped attachment MIME type on the attachment-validation warning page (CVE-2026-54432) and an SSRF bypass via specific local address URLs (CVE-2026-54433). DirectAdmin servers running Roundcube webmail should update through CustomBuild.

High 4.7 CVSS
DirectAdmin

Etkilenen Sürümler

1.7.2

Varsayılan Güncelleme Komutu

cd /usr/local/directadmin/custombuild && ./build update_versions

SharedLicense lisansı altında bunun anlamı

The stored XSS runs script in a webmail user's browser session, and the SSRF bypass can be used to reach internal addresses — both meaningful on shared mail servers.


		
			
			
				
					
						Security updates 1.6.17 and 1.7.2 released
					
				

				Free and open source webmail software for the masses, written in PHP

				
					
						
							
						
					
					roundcube.net
				
			
		
	

Security updates 1.6.17 and 1.7.2 released​

Published: 05 July 2026

We just published security updates to the 1.6 LTS and 1.7 versions of Roundcube Webmail. They both contain fixes for recently reported security vulnerabilities.

Security fixes​

  • Fix an infinite loop in TNEF (winmail.dat) decoder (#10193), reported by stafra.
  • Fix various vulnerabilities in the password plugin using session-injected username, reported by Glendaenri and peppersghost.
  • Fix stored XSS via unescaped attachment MIME type on the attachment-validation warning page [CVE-2026-54432], reported by Bohdan Kurinnoy, Samsung R&D Institute Ukraine (SRUKR).
  • Fix SSRF bypass via specific local address URLs – two new cases, reported by Leenear.
  • Fix zero-click stored XSS in plain-text rendering [CVE-2026-54433], reported by Bohdan Kurinnoy, Samsung R&D Institute Ukraine (SRUKR).
  • Fix DoS via crafted compressed-RTF size in the TNEF (winmail.dat) file, reported by h0rk1p.

See the full changelogs in the release notes on the Github download pages for the updated versions1.6.17 and 1.7.2.

We strongly recommend to update all productive installations of Roundcube 1.6.x and 1.7.x with this new versions.

Sıkça Sorulan Sorular

What is CVE-2026-54432?
It is a stored XSS in Roundcube caused by an unescaped attachment MIME type shown on the attachment-validation warning page (CWE-79, CVSS 4.7). It was reported by Bohdan Kurinnoy of Samsung R&D Institute Ukraine.
What is CVE-2026-54433?
It is an SSRF bypass in Roundcube, fixed alongside CVE-2026-54432 in the 1.6.17 and 1.7.2 security releases, which closes newly reported cases of local-address URL filtering being bypassed.
Which Roundcube versions fix these CVEs?
Roundcube 1.7.2 (current branch) and 1.6.17 (1.6 LTS), both published 5 July 2026. The same release also fixed an infinite loop in the TNEF winmail.dat decoder and session-injected username issues in the password plugin.
How do I update Roundcube on DirectAdmin?
Run: cd /usr/local/directadmin/custombuild && ./build update_versions — CustomBuild ships the fixed Roundcube. Confirm the version via CustomBuild's versions output.

Sisteminizi güvenlik açıkları açısından kontrol edin

Size uygun tam düzeltme komutlarını görmek için ürününüzü ve işletim sisteminizi seçin.

Sisteminizi Kontrol Edin