{"id":"openSUSE-SU-2026:20586-1","summary":"Security update for roundcubemail","details":"This update for roundcubemail fixes the following issues:\n\nChanges in roundcubemail:\n\n- update to 1.6.15\n  This is a security update to the stable version 1.6 of Roundcube Webmail.\n  It provides fixes to some regressions introduced in the previous release\n  as well a recently reported security vulnerability:\n\n    SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke, reported by class_nzm.\n\n  This version is considered stable and we recommend to update all productive\n  installations of Roundcube 1.6.x with it. Please do backup your data before updating!\n\n  + Fix regression where mail search would fail on non-ascii search criteria (#10121)\n  + Fix regression where some data url images could get ignored/lost (#10128)\n  + Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke (bsc#1261157)\n\n- update to 1.6.14\n  This is a security update to the stable version 1.6 of Roundcube Webmail.\n  + Fix Postgres connection using IPv6 address (#10104)\n  + Security: Fix pre-auth arbitrary file write via unsafe deserialization in redis/memcache session handler\n    (bsc#1261488, CVE-2026-35537)\n  + Security: Fix bug where a password could get changed without providing the old password\n  + Security: Fix IMAP Injection + CSRF bypass in mail search\n  + Security: Fix remote image blocking bypass via various SVG animate attributes\n  + Security: Fix remote image blocking bypass via a crafted body background attribute\n  + Security: Fix fixed position mitigation bypass via use of !important\n  + Security: Fix XSS issue in a HTML attachment preview\n  + Security: Fix SSRF + Information Disclosure via stylesheet links to a local network hosts\n","modified":"2026-04-22T18:27:20.626228Z","published":"2026-04-17T09:15:58Z","related":["CVE-2026-35537"],"upstream":["CVE-2026-35537"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261157"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261488"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35537"}],"affected":[{"package":{"name":"roundcubemail","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/roundcubemail&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.15-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"roundcubemail":"1.6.15-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20586-1.json"}}],"schema_version":"1.7.5"}