Bug 2500040 (CVE-2026-62643)
| Summary: | CVE-2026-62643 roundcubemail: Roundcube Webmail: Server-Side Request Forgery via insufficient CSS sanitization | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Roundcube Webmail. Insufficient sanitization of Cascading Style Sheets (CSS) within HTML email messages allows a remote attacker to perform Server-Side Request Forgery (SSRF) or disclose sensitive information. This vulnerability occurs when stylesheet links point to local network hosts, potentially enabling access to internal resources or sensitive data. This issue is a result of incomplete fixes for previously identified vulnerabilities.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2500072, 2500073 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-07-14 17:01:36 UTC
|