Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. Evolution's mail display trusted-JavaScript handler (Evo.MailDisplayBindDOM(), in the WebKitGTK web-extension layer) binds a privileged click handler to any DOM element matching the CSS class used for vCard formatter controls, without verifying that the element actually originated from Evolution's own vCard rendering. A malicious HTML email can include a spoofed control carrying a custom "evo-iframe-uri" attribute set to a "javascript:" URL. Because this attribute is not one of the URL attributes WebKit's markup filter recognizes, a "javascript:" value in it survives sanitization even when script execution in mail content is disabled (enable-javascript-markup= false). When a victim clicks the spoofed control, the trusted handler assigns the attacker-controlled value to an iframe's "src", triggering a dynamic javascript: navigation that WebKit executes without checking the document's script-markup policy. This allows an attacker to execute arbitrary JavaScript in the mail-viewing context via a single click on a crafted email, bypassing the restriction that is meant to prevent script execution when viewing mail. Fixed upstream in Evolution 3.62.0. Upstream report: https://gitlab.gnome.org/GNOME/evolution/-/work_items/3388
Thanks for a bug report. The rawhide and f45 will get the fix with the 3.62.0 release (to happen tomorrow), where it'll be included. The f44 and f43 need a backport.
FEDORA-2026-99a4ff5552 (evolution-3.60.2-2.fc44) has been submitted as an update to Fedora 44. https://bodhi.fedoraproject.org/updates/FEDORA-2026-99a4ff5552
FEDORA-2026-1ea9bbcb29 (evolution-3.58.3-2.fc43) has been submitted as an update to Fedora 43. https://bodhi.fedoraproject.org/updates/FEDORA-2026-1ea9bbcb29
FEDORA-2026-1ea9bbcb29 has been pushed to the Fedora 43 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-1ea9bbcb29` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-1ea9bbcb29 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-99a4ff5552 has been pushed to the Fedora 44 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-99a4ff5552` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-99a4ff5552 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-5debc0de2b (evolution-3.62.0-1.fc45, evolution-data-server-3.62.0-1.fc45, and 1 more) has been submitted as an update to Fedora 45. https://bodhi.fedoraproject.org/updates/FEDORA-2026-5debc0de2b
FEDORA-2026-5debc0de2b has been pushed to the Fedora 45 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-5debc0de2b` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-5debc0de2b See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-1ea9bbcb29 (evolution-3.58.3-2.fc43) has been pushed to the Fedora 43 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-2026-99a4ff5552 (evolution-3.60.2-2.fc44) has been pushed to the Fedora 44 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-2026-5debc0de2b (evolution-3.62.0-1.fc45, evolution-data-server-3.62.0-1.fc45, and 1 more) has been pushed to the Fedora 45 stable repository. If problem still persists, please make note of it in this bug report.