{"id":"USN-8223-1","summary":"roundcube vulnerabilities","details":"It was discovered that Roundcube Webmail mishandled Punycode xn-- domain names.\nAn attacker could possibly use this issue to cause a homograph attack. (CVE-2019-15237)\n\nIt was discovered that Roundcube Webmail did not properly sanitize certain\nattributes when handling CSS within HTML messages and certain SVG attributes.\nAn attacker could possibly use this issue to cause a cross-site scripting attack.\n(CVE-2024-38356, CVE-2024-38357)\n\nIt was discovered that Roundcube Webmail did not properly sanitize certain HTML\nattributes when rendering e-mail messages. An attacker could possibly use this\nissue to cause a cross-site scripting attack. (CVE-2024-42008)\n\nIt was discovered that Roundcube Webmail did not properly filter certain CSS token\nsequences within rendered e-mail messages. An attacker could possibly use this\nissue to obtain sensitive information. (CVE-2024-42010)\n\nIt was discovered that Roundcube Webmail did not properly treat an SVG\ntag as an image source within its HTML sanitizer. An attacker could possibly use\nthis issue to bypass remote image blocking to track email open actions or\npotentially bypass access control. (CVE-2026-25916)\n\nIt was discovered that Roundcube Webmail did not properly handle comments within\nCascading Style Sheets (CSS). An attacker could possibly use this issue to perform\na CSS injection attack. (CVE-2026-26079)","modified":"2026-04-30T10:00:02.772086882Z","published":"2026-04-29T13:50:15Z","related":["UBUNTU-CVE-2019-15237","UBUNTU-CVE-2024-38356","UBUNTU-CVE-2024-38357","UBUNTU-CVE-2024-42008","UBUNTU-CVE-2024-42010","UBUNTU-CVE-2026-25916","UBUNTU-CVE-2026-26079"],"upstream":["CVE-2019-15237","CVE-2024-38356","CVE-2024-38357","CVE-2024-42008","CVE-2024-42010","CVE-2026-25916","CVE-2026-26079","UBUNTU-CVE-2019-15237","UBUNTU-CVE-2024-38356","UBUNTU-CVE-2024-38357","UBUNTU-CVE-2024-42008","UBUNTU-CVE-2024-42010","UBUNTU-CVE-2026-25916","UBUNTU-CVE-2026-26079"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8223-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2019-15237"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-38356"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-38357"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-42008"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-42010"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-25916"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-26079"}],"affected":[{"package":{"name":"roundcube","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/roundcube@1.2~beta+dfsg.1-0ubuntu1+esm8?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2~beta+dfsg.1-0ubuntu1+esm8"}]}],"versions":["1.1.1+dfsg.1-2","1.1.2+dfsg.1-5","1.1.3+dfsg.1-1","1.1.4+dfsg.1-1","1.2~beta+dfsg.1-0ubuntu1","1.2~beta+dfsg.1-0ubuntu1+esm1","1.2~beta+dfsg.1-0ubuntu1+esm2","1.2~beta+dfsg.1-0ubuntu1+esm3","1.2~beta+dfsg.1-0ubuntu1+esm4","1.2~beta+dfsg.1-0ubuntu1+esm5","1.2~beta+dfsg.1-0ubuntu1+esm6","1.2~beta+dfsg.1-0ubuntu1+esm7"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"1.2~beta+dfsg.1-0ubuntu1+esm8","binary_name":"roundcube"},{"binary_version":"1.2~beta+dfsg.1-0ubuntu1+esm8","binary_name":"roundcube-core"},{"binary_version":"1.2~beta+dfsg.1-0ubuntu1+esm8","binary_name":"roundcube-mysql"},{"binary_version":"1.2~beta+dfsg.1-0ubuntu1+esm8","binary_name":"roundcube-pgsql"},{"binary_version":"1.2~beta+dfsg.1-0ubuntu1+esm8","binary_name":"roundcube-plugins"},{"binary_version":"1.2~beta+dfsg.1-0ubuntu1+esm8","binary_name":"roundcube-sqlite3"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2019-15237"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2024-42010"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-26079"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8223-1.json"}},{"package":{"name":"roundcube","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/roundcube@1.3.6+dfsg.1-1ubuntu0.1~esm8?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.6+dfsg.1-1ubuntu0.1~esm8"}]}],"versions":["1.3.0+dfsg.1-1","1.3.1+dfsg.1-1","1.3.3+dfsg.1-1","1.3.3+dfsg.1-2","1.3.6+dfsg.1-1","1.3.6+dfsg.1-1ubuntu0.1~esm1","1.3.6+dfsg.1-1ubuntu0.1~esm2","1.3.6+dfsg.1-1ubuntu0.1~esm3","1.3.6+dfsg.1-1ubuntu0.1~esm4","1.3.6+dfsg.1-1ubuntu0.1~esm5","1.3.6+dfsg.1-1ubuntu0.1~esm6","1.3.6+dfsg.1-1ubuntu0.1~esm7"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"1.3.6+dfsg.1-1ubuntu0.1~esm8","binary_name":"roundcube"},{"binary_version":"1.3.6+dfsg.1-1ubuntu0.1~esm8","binary_name":"roundcube-core"},{"binary_version":"1.3.6+dfsg.1-1ubuntu0.1~esm8","binary_name":"roundcube-mysql"},{"binary_version":"1.3.6+dfsg.1-1ubuntu0.1~esm8","binary_name":"roundcube-pgsql"},{"binary_version":"1.3.6+dfsg.1-1ubuntu0.1~esm8","binary_name":"roundcube-plugins"},{"binary_version":"1.3.6+dfsg.1-1ubuntu0.1~esm8","binary_name":"roundcube-sqlite3"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2019-15237"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2024-42010"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-25916"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-26079"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8223-1.json"}},{"package":{"name":"roundcube","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/roundcube@1.4.3+dfsg.1-1ubuntu0.1~esm8?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.3+dfsg.1-1ubuntu0.1~esm8"}]}],"versions":["1.3.8+dfsg.1-2","1.3.10+dfsg.1-1","1.4.1+dfsg.1-2","1.4.2+dfsg.1-1","1.4.2+dfsg.1-2","1.4.3+dfsg.1-1","1.4.3+dfsg.1-1ubuntu0.1~esm1","1.4.3+dfsg.1-1ubuntu0.1~esm2","1.4.3+dfsg.1-1ubuntu0.1~esm3","1.4.3+dfsg.1-1ubuntu0.1~esm4","1.4.3+dfsg.1-1ubuntu0.1~esm5","1.4.3+dfsg.1-1ubuntu0.1~esm6","1.4.3+dfsg.1-1ubuntu0.1~esm7"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"1.4.3+dfsg.1-1ubuntu0.1~esm8","binary_name":"roundcube"},{"binary_version":"1.4.3+dfsg.1-1ubuntu0.1~esm8","binary_name":"roundcube-core"},{"binary_version":"1.4.3+dfsg.1-1ubuntu0.1~esm8","binary_name":"roundcube-mysql"},{"binary_version":"1.4.3+dfsg.1-1ubuntu0.1~esm8","binary_name":"roundcube-pgsql"},{"binary_version":"1.4.3+dfsg.1-1ubuntu0.1~esm8","binary_name":"roundcube-plugins"},{"binary_version":"1.4.3+dfsg.1-1ubuntu0.1~esm8","binary_name":"roundcube-sqlite3"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:20.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2019-15237"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2024-42010"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-25916"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-26079"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8223-1.json"}},{"package":{"name":"roundcube","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/roundcube@1.5.0+dfsg.1-2ubuntu0.1~esm6?arch=source&distro=esm-apps/jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.0+dfsg.1-2ubuntu0.1~esm6"}]}],"versions":["1.4.11+dfsg.1-4","1.5.0+dfsg.1-2","1.5.0+dfsg.1-2ubuntu0.1~esm1","1.5.0+dfsg.1-2ubuntu0.1~esm2","1.5.0+dfsg.1-2ubuntu0.1~esm3","1.5.0+dfsg.1-2ubuntu0.1~esm4","1.5.0+dfsg.1-2ubuntu0.1~esm5"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"1.5.0+dfsg.1-2ubuntu0.1~esm6","binary_name":"roundcube"},{"binary_version":"1.5.0+dfsg.1-2ubuntu0.1~esm6","binary_name":"roundcube-core"},{"binary_version":"1.5.0+dfsg.1-2ubuntu0.1~esm6","binary_name":"roundcube-mysql"},{"binary_version":"1.5.0+dfsg.1-2ubuntu0.1~esm6","binary_name":"roundcube-pgsql"},{"binary_version":"1.5.0+dfsg.1-2ubuntu0.1~esm6","binary_name":"roundcube-plugins"},{"binary_version":"1.5.0+dfsg.1-2ubuntu0.1~esm6","binary_name":"roundcube-sqlite3"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:22.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2024-38356"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2024-38357"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2024-42008"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2024-42010"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-25916"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-26079"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8223-1.json"}},{"package":{"name":"roundcube","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/roundcube@1.6.6+dfsg-2ubuntu0.1+esm3?arch=source&distro=esm-apps/noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.6+dfsg-2ubuntu0.1+esm3"}]}],"versions":["1.6.2+dfsg-1","1.6.4+dfsg-1","1.6.5+dfsg-1","1.6.6+dfsg-1","1.6.6+dfsg-2","1.6.6+dfsg-2ubuntu0.1","1.6.6+dfsg-2ubuntu0.1+esm1","1.6.6+dfsg-2ubuntu0.1+esm2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"1.6.6+dfsg-2ubuntu0.1+esm3","binary_name":"roundcube"},{"binary_version":"1.6.6+dfsg-2ubuntu0.1+esm3","binary_name":"roundcube-core"},{"binary_version":"1.6.6+dfsg-2ubuntu0.1+esm3","binary_name":"roundcube-mysql"},{"binary_version":"1.6.6+dfsg-2ubuntu0.1+esm3","binary_name":"roundcube-pgsql"},{"binary_version":"1.6.6+dfsg-2ubuntu0.1+esm3","binary_name":"roundcube-plugins"},{"binary_version":"1.6.6+dfsg-2ubuntu0.1+esm3","binary_name":"roundcube-sqlite3"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:24.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2024-38356"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2024-38357"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2024-42008"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2024-42010"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-25916"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-26079"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8223-1.json"}}],"schema_version":"1.7.5"}