{"id":"CVE-2026-35545","details":"An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.","aliases":["GHSA-w846-74jr-76cv"],"modified":"2026-07-15T01:48:54.786392275Z","published":"2026-04-03T04:02:06.765Z","database_specific":{"cna_assigner":"mitre","cwe_ids":["CWE-669"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35545.json"},"references":[{"type":"WEB","url":"https://github.com/roundcube/roundcubemail/releases/tag/1.5.15"},{"type":"WEB","url":"https://github.com/roundcube/roundcubemail/releases/tag/1.6.15"},{"type":"WEB","url":"https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc6"},{"type":"WEB","url":"https://roundcube.net/news/2026/03/29/security-updates-1.7-rc6-1.6.15-1.5.15"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35545.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35545"},{"type":"FIX","url":"https://github.com/roundcube/roundcubemail/commit/7ad62de184368bf42c0f522d1aacc030f5ddcc46"},{"type":"FIX","url":"https://github.com/roundcube/roundcubemail/commit/9d18d524f3cc211003fc99e2e54eed09a2f3da88"},{"type":"FIX","url":"https://github.com/roundcube/roundcubemail/commit/fe1320b199d3a2f58351bb699c9ed4316e73221b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/roundcube/roundcubemail","events":[{"introduced":"0"},{"fixed":"cecc5071744f964c03e303b4253f8deb0ef72b98"},{"introduced":"993b888afe29c383bf45c84f17090f4db96367ba"},{"fixed":"9d18d524f3cc211003fc99e2e54eed09a2f3da88"},{"fixed":"7ad62de184368bf42c0f522d1aacc030f5ddcc46"},{"fixed":"fe1320b199d3a2f58351bb699c9ed4316e73221b"},{"fixed":"018bcf77d517590643c6487ff2f048253160b070"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.5.15"},{"introduced":"1.6.0"},{"fixed":"1.6.15"}]}}],"versions":["1.7-rc5","1.5.14","1.6.14","1.7-rc4","1.5.13","1.6.13","1.7-rc3","1.7-rc2","1.5.12","1.6.12","1.7-rc","1.5.11","1.7-beta2","1.7-beta","1.5.10","1.6.11","1.6.10","1.5.9","1.6.9","1.5.8","1.6.8","1.5.7","1.6.7","1.6.6","1.5.6","1.6.5","1.5.5","1.6.4","1.6.3","1.5.4","1.6.2","1.6.1","1.5.3","1.6.0","1.6-beta","1.5.2","1.5.1","1.5.0","1.5-rc","1.5-beta","1.4-rc2","1.4-rc1","1.4-beta","1.3-beta","1.2-rc","1.2-beta","1.1.0","1.1-rc","1.1-beta","v0.1-beta2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35545.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}