We just published security updates to the 1.7 and 1.6 LTS versions of
Roundcube Webmail. They both contain fixes for recently reported
security vulnerabilities.
Security fixes:
- Fix CSS declaration smuggling via un-encoded ampersand emission,
reported by Zach Hanley of Horizon3.ai
- Fix CSS property injection via body `background` attribute, reported
by zenithhostingevan
- Fix email header injection via bare CR in the subject field, reported
by CVE-Hunter-Leo
- Fix email header injection via C-escape \r in the recipient display
name, reported by dogeshark
- Fix email header injection via identity's organization field, reported
by dogeshark
- Fix zero-click stored XSS via TNEF MIME tag injection in the
attachment URL, reported by nakko
- Fix XSS in the HTML editor using text/enriched part content, reported
by Joshua Rogers
- Fix cross-user access in contact group membership (add/remove) in the
SQL address book, reported by Joshua Rogers
- Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL,
reported by nept1337
- Fix remote content blocking bypass via CSS escapes in FuncIRI
attributes, reported by neoxed
- Fix remote-content blocker bypass via SVG SMIL src animation
- Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped
IPv4 addresses, reported by faceless0x7 and Harish Annavisamy
See the full changelogs in the release notes on the Github download
pages for the updated versions.
https://github.com/roundcube/roundcubemail/releases/tag/1.7.4https://github.com/roundcube/roundcubemail/releases/tag/1.6.19
We strongly recommend to update all productive installations of
Roundcube 1.6.x and 1.7.x with this new versions.
--
Alec
Note: Message originally sent on 2026-08-09, but not delivered because
of the mailing list issues.
We just published security updates to the 1.7 and 1.6 LTS versions of
Roundcube Webmail. They both contain fixes for recently reported
security vulnerabilities.
Security fixes:
- Add basic validation for content proxied by the css proxy
- Fix SSRF bypass via specific local address URLs using 100.64.0.0/10
and fe80::/10 nets, reported by Dmytro Ivanenko
- Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames
evading is_local_url() check, reported by Milan Hoppe
- Fix remote content blocking bypass via unclosed url() in a FuncIRI
attribute, reported by Milan Hoppe
- Fix LDAP filter injection via unescaped %u/%fu/%d substitution into
the `search_filter`, reported by Milan Hoppe
- Fix arbitrary Sieve script injection via a filter rule name bypassing
`managesieve_disabled_actions`, reported by Milan Hoppe
- Fix RCE via cmd_learn driver of markasjunk plugin, reported by nept1337
- Fix IMAP command injection via mail search and LITERAL+ byte-count
desynchronization, reported by Zach Hanley of Horizon3.ai
- Fix password's modoboa driver leak of an authentication token to a
user-controlled host, reported by meifukun
- Fix stored XSS in "Add to address book" action, reported by Paulos
Yibelo from pwn.ai
- Fix HTML/CSS sanitization bypass via SVG animate `by` attribute,
reported by vectrain
See the full changelogs in the release notes on the Github download
pages for the updated versions.
https://github.com/roundcube/roundcubemail/releases/tag/1.7.3https://github.com/roundcube/roundcubemail/releases/tag/1.6.18
We strongly recommend to update all productive installations of
Roundcube 1.6.x and 1.7.x with this new versions.
--
Alec
We just published security updates to the 1.7 and 1.6 LTS versions of
Roundcube Webmail. They both contain fixes for recently reported
security vulnerabilities.
Security fixes:
- Fix an infinite loop in TNEF (winmail.dat) decoder (#10193), reported
by stafra.
- Fix various vulnerabilities in the password plugin using
session-injected username, reported by Glendaenri and peppersghost.
- Fix stored XSS via unescaped attachment MIME type on the
attachment-validation warning page [CVE-2026-54432], reported by Bohdan
Kurinnoy, Samsung R&D Institute Ukraine (SRUKR).
- Fix SSRF bypass via specific local address URLs - two new cases,
reported by Leenear.
- Fix zero-click stored XSS in plain-text rendering [CVE-2026-54433],
reported by Bohdan Kurinnoy, Samsung R&D Institute Ukraine (SRUKR).
- Fix DoS via crafted compressed-RTF size in the TNEF (winmail.dat)
file, reported by h0rk1p.
See the full changelogs in the release notes on the Github download
pages for the updated versions.
https://github.com/roundcube/roundcubemail/releases/tag/1.7.2https://github.com/roundcube/roundcubemail/releases/tag/1.6.17
We strongly recommend to update all productive installations of
Roundcube 1.6.x and 1.7.x with this new versions.
--
Alec
Here's the same message with corrected subject. Sorry about that.
We just published security updates to the 1.7 and 1.6 LTS versions of
Roundcube Webmail. They both contain fixes for recently reported
security vulnerabilities.
Security fixes:
- Fix stored XSS/HTML/CSS injection in subject field of the draft
restore dialog, reported by zazy
- Fix CSS injection bypass in HTML sanitizer via SVG `<animate
attributeName="style">`, reported by wooseokdotkim
- Fix pre-auth SQL injection in virtuser_query plugin via preg_replace
backslash escape bypass, reported by skull
- Fix SSRF bypass via specific local address URLs
- Fix local/private URL fetch bypass when remote resources were not
allowed, reported by Orange Cyberdefense Vulnerability Disclosure Team
- Fix bypass of remote image blocking via CSS var(), reported by Geame
- Fix pre-auth arbitrary file delete via redis/memcache session
poisoning bypass, reported by valent1
- Fix code injection vulnerability - remove support for code evaluation
in LDAP `autovalues` option, reported by Glendaenri
See the full changelogs in the release notes on the Github download
pages for the updated versions 1.7.1 and 1.6.16.
https://github.com/roundcube/roundcubemail/releases/tag/1.7.1https://github.com/roundcube/roundcubemail/releases/tag/1.6.16
We strongly recommend to update all productive installations of
Roundcube 1.6.x and 1.7.x with this new versions.
--
Alec
We just published security updates to the 1.7 and 1.6 LTS versions of
Roundcube Webmail. They both contain fixes for recently reported
security vulnerabilities.
Security fixes:
- Fix stored XSS/HTML/CSS injection in subject field of the draft
restore dialog, reported by zazy
- Fix CSS injection bypass in HTML sanitizer via SVG `<animate
attributeName="style">`, reported by wooseokdotkim
- Fix pre-auth SQL injection in virtuser_query plugin via preg_replace
backslash escape bypass, reported by skull
- Fix SSRF bypass via specific local address URLs
- Fix local/private URL fetch bypass when remote resources were not
allowed, reported by Orange Cyberdefense Vulnerability Disclosure Team
- Fix bypass of remote image blocking via CSS var(), reported by Geame
- Fix pre-auth arbitrary file delete via redis/memcache session
poisoning bypass, reported by valent1
- Fix code injection vulnerability - remove support for code evaluation
in LDAP `autovalues` option, reported by Glendaenri
See the full changelogs in the release notes on the Github download
pages for the updated versions 1.7.1 and 1.6.16.
https://github.com/roundcube/roundcubemail/releases/tag/1.7.1https://github.com/roundcube/roundcubemail/releases/tag/1.6.16
We strongly recommend to update all productive installations of
Roundcube 1.6.x and 1.7.x with this new versions.
--
Alec
This is the stable release of the next major version 1.7 of Roundcube
Webmail.
After almost four years of development we introduce a few breaking
changes, some new features, and bring support for recent PHP versions.
With automated code style and quality checks, removed code bloat and
updated dependencies, we hope for even more codebase quality.
Some noteworthy changes are:
- Mandatory `public_html/` entry-point for HTTP servers, protecting all
installations better.
- Improved OAuth2/OIDC support (e.g. support for OIDC discovery, OIDC
logout).
- Markdown mail rendering and composing.
- A quick actions mouse-over menu on the messages list.
- Advanced mail search syntax.
## Breaking Changes
- Dropped support for PHP < 8.1.
- Dropped support for Internet Explorer.
- Dropped support for MS SQL Server and Oracle.
- `public_html/` entry-point made mandatory, all static resources are
served via `public_html/static.php`.
- Removed `apc` cache driver (replaced by `apcu` cache driver).
- Changed `smtp_log` option default value to `false`.
- Removed `contact_search_name` option in favor of
`contactlist_name_template`.
- Replaced session property `changed` by `expires_at`.
- Removed the (insecure) virtualmin password driver.
This release is considered stable and we encourage you to update your
productive installations after carefully testing the upgrade scenario.
With the release of Roundcube 1.7.0, the previous stable release branch
1.6.x changes into an LTS (low maintenance) mode which means it will
only receive important security updates. The 1.5.x series is no longer
supported and maintained.
And don't forget to backup your data before installing it!
You can download it from https://roundcube.net
Cheers,
Alec
We just published security updates to the 1.6 and 1.5 LTS versions of
Roundcube Webmail, as well as a release candidate for coming 1.7.
It provides fixes to some regressions introduced in the previous release
as well a recently reported security vulnerability.
## Security fixes
- SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via
fill/filter/stroke, reported by class_nzm.
See the full changelogs in the release notes on the Github download
pages for the updated versions
- https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc6
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.15
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.15
We strongly recommend to update your productive installations of
Roundcube with this new versions.
--
Alec
We just published security updates to the 1.6 and 1.5 LTS versions of
Roundcube Webmail, as well as a release candidate for coming 1.7.
They contain fixes for recently reported set of security vulnerabilities.
## Security fixes
- Fix pre-auth arbitrary file write via unsafe deserialization in
redis/memcache session handler, reported by y0us.
- Fix bug where a password could get changed without providing the old
password, reported by flydragon777.
- Fix IMAP Injection + CSRF bypass in mail search, reported by Martila
Security Research Team.
- Fix remote image blocking bypass via various SVG animate attributes,
reported by nullcathedral.
- Fix remote image blocking bypass via a crafted body background
attribute, reported by nullcathedral.
- Fix fixed position mitigation bypass via use of !important, reported
by nullcathedral.
- Fix XSS issue in a HTML attachment preview, reported by aikido_security.
- Fix SSRF + Information Disclosure via stylesheet links to a local
network hosts, reported by Georgios Tsimpidas (aka Frey), Security
Researcher at https://i0.rs/.
See the full changelogs in the release notes on the Github download
pages for the updated versions
- https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc5
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.14
- https://github.com/roundcube/roundcubemail/releases/tag/1.5.14
We strongly recommend to update your productive installations of
Roundcube with this new versions.
--
Alec
We just published the fourth release candidate for the next major version 1.7 of Roundcube webmail.
This release fixes two minor issues, it's mostly published to fix a file permission problem in the previous release v1.7-rc3.
The changes are:
- Ensure correct file permissions when building a release.
- Installer: Fix broken link to download the created configuration file (#10092)
The tarballs can be downloaded [from roundcube.net/download](https://roundcube.net/download/).
Or directly from [the release page at github.com](https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc4).
We believe it is production ready, but we recommend to test it on a separate environment.
Migrate existing configs with either the `installto.sh` or the `update.sh` scripts.
And don't forget to backup your data before installing it!
Regards, Pablo
--
Pablo Zimdahl
Software Engineer
oOo Nextcloud - Regain control over your data
pablo.zimdahl(a)nextcloud.com
nextcloud.com
+49 711 25 24 28 90
Nextcloud GmbH
Hauptmannsreute 44A, 70192 Stuttgart, Germany
GF: Frank Karlitschek
HRB 227086 (AG München)
We just published the third release candidate for the next major version 1.7 of Roundcube webmail.
This release fixes two security issues, and contains a few more fixes for several issues.
The security fixes are:
- Fix CSS injection vulnerability reported by CERT Polska.
- Fix remote image blocking bypass via SVG content reported by nullcathedral.
For the full changelog please see the release page: https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc3.
The tarballs can be downloaded via roundcube.net: https://roundcube.net/download/
Or directly from the release page at github.com: https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc3
We believe it is production ready, but we recommend to test it on a separate environment.
Migrate existing configs with either the `installto.sh` or the `update.sh` scripts.
And don't forget to backup your data before installing it!
Regards, Pablo
--
Pablo Zimdahl
Software Engineer
oOo Nextcloud - Regain control over your data
pablo.zimdahl(a)nextcloud.com
nextcloud.com
+49 711 25 24 28 90
Nextcloud GmbH
Hauptmannsreute 44A, 70192 Stuttgart, Germany
GF: Frank Karlitschek
HRB 227086 (AG München)