Debian Package Tracker
Register | Log in
Subscribe

roundcube

skinnable AJAX based webmail solution for IMAP servers - metapackage

Choose email to subscribe with

general
  • source: roundcube (main)
  • version: 1.6.18+dfsg-1
  • maintainer: Debian Roundcube Maintainers (archive) (DMD)
  • uploaders: Guilhem Moulin [DMD] – Sandro Knauß [DMD] – Vincent Bernat [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.4.15+dfsg.1-1+deb11u4
  • o-o-sec: 1.4.15+dfsg.1-1+deb11u10
  • o-o-p-u: 1.4.15+dfsg.1-1+deb11u4
  • oldstable: 1.6.5+dfsg-1+deb12u9
  • old-sec: 1.6.5+dfsg-1+deb12u10
  • old-p-u: 1.6.5+dfsg-1+deb12u9
  • stable: 1.6.16+dfsg-0+deb13u1
  • stable-sec: 1.6.17+dfsg-0+deb13u1
  • stable-p-u: 1.6.17+dfsg-0+deb13u1
  • testing: 1.6.18+dfsg-1
  • unstable: 1.6.18+dfsg-1
versioned links
  • 1.4.15+dfsg.1-1+deb11u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.15+dfsg.1-1+deb11u10: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.5+dfsg-1+deb12u9: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.5+dfsg-1+deb12u10: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.16+dfsg-0+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.17+dfsg-0+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.18+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • roundcube (5 bugs: 0, 5, 0, 0)
  • roundcube-core (11 bugs: 0, 7, 4, 0)
  • roundcube-mysql
  • roundcube-pgsql
  • roundcube-plugins
  • roundcube-sqlite3
action needed
A new upstream version is available: 1.7.3 high
A new upstream version 1.7.3 is available, you should consider packaging it.
Created: 2026-08-11 Last update: 2026-08-24 03:03
10 security issues in trixie high

There are 10 open security issues in trixie.

10 important issues:
  • CVE-2026-74997: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
  • CVE-2026-74998: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
  • CVE-2026-74999: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
  • CVE-2026-75000: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
  • CVE-2026-75002: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.
  • CVE-2026-75003: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.
  • CVE-2026-75004: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.
  • CVE-2026-75006: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.
  • CVE-2026-75007: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.
  • CVE-2026-75010: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
Created: 2026-08-10 Last update: 2026-08-18 04:31
11 security issues in bullseye high

There are 11 open security issues in bullseye.

10 important issues:
  • CVE-2026-74997: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
  • CVE-2026-74998: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
  • CVE-2026-74999: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
  • CVE-2026-75000: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
  • CVE-2026-75002: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.
  • CVE-2026-75003: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.
  • CVE-2026-75004: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.
  • CVE-2026-75006: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.
  • CVE-2026-75007: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.
  • CVE-2026-75010: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
1 ignored issue:
  • CVE-2019-15237: Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
Created: 2026-08-10 Last update: 2026-08-18 04:31
10 security issues in bookworm high

There are 10 open security issues in bookworm.

10 important issues:
  • CVE-2026-74997: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
  • CVE-2026-74998: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
  • CVE-2026-74999: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
  • CVE-2026-75000: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
  • CVE-2026-75002: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.
  • CVE-2026-75003: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.
  • CVE-2026-75004: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.
  • CVE-2026-75006: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.
  • CVE-2026-75007: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.
  • CVE-2026-75010: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
Created: 2026-08-10 Last update: 2026-08-18 04:31
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2026-08-15 Last update: 2026-08-24 03:00
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2026-07-06 Last update: 2026-07-06 04:48
debian/patches: 1 patch to forward upstream low

Among the 27 debian patches available in version 1.6.18+dfsg-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2024-12-21 Last update: 2026-08-11 12:18
news
[rss feed]
  • [2026-08-17] roundcube 1.6.18+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-10] Accepted roundcube 1.6.18+dfsg-1 (source) into unstable (Guilhem Moulin)
  • [2026-07-22] Accepted roundcube 1.6.17+dfsg-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-07-21] Accepted roundcube 1.4.15+dfsg.1-1+deb11u10 (source) into oldoldstable-security (Guilhem Moulin)
  • [2026-07-21] Accepted roundcube 1.6.5+dfsg-1+deb12u10 (source) into oldstable-security (Guilhem Moulin)
  • [2026-07-19] Accepted roundcube 1.6.17+dfsg-0+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-07-08] roundcube 1.6.17+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-05] Accepted roundcube 1.6.17+dfsg-1 (source) into unstable (Guilhem Moulin)
  • [2026-05-29] roundcube 1.6.16+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-28] Accepted roundcube 1.6.5+dfsg-1+deb12u9 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-05-28] Accepted roundcube 1.6.16+dfsg-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-05-28] Accepted roundcube 1.4.15+dfsg.1-1+deb11u9 (source) into oldoldstable-security (Guilhem Moulin)
  • [2026-05-27] Accepted roundcube 1.6.16+dfsg-0+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-05-27] Accepted roundcube 1.6.5+dfsg-1+deb12u9 (source) into oldstable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-05-24] Accepted roundcube 1.6.16+dfsg-1 (source) into unstable (Guilhem Moulin)
  • [2026-05-11] roundcube REMOVED from testing (Debian testing watch)
  • [2026-04-06] Accepted roundcube 1.6.5+dfsg-1+deb12u8 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-04-06] Accepted roundcube 1.6.15+dfsg-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-04-04] Accepted roundcube 1.6.15+dfsg-0+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-04-04] Accepted roundcube 1.6.5+dfsg-1+deb12u8 (source) into oldstable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-04-02] roundcube 1.6.15+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-30] Accepted roundcube 1.4.15+dfsg.1-1+deb11u8 (source) into oldoldstable-security (Guilhem Moulin)
  • [2026-03-30] Accepted roundcube 1.6.15+dfsg-1 (source) into unstable (Guilhem Moulin)
  • [2026-03-24] roundcube 1.6.14+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-20] Accepted roundcube 1.6.14+dfsg-1 (source) into unstable (Guilhem Moulin)
  • [2026-02-21] Accepted roundcube 1.6.5+dfsg-1+deb12u7 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-02-19] Accepted roundcube 1.6.13+dfsg-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-02-17] Accepted roundcube 1.4.15+dfsg.1-1+deb11u7 (source) into oldoldstable-security (Guilhem Moulin)
  • [2026-02-17] Accepted roundcube 1.6.5+dfsg-1+deb12u7 (source) into oldstable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-02-17] Accepted roundcube 1.6.13+dfsg-0+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • 1
  • 2
bugs [bug history graph]
  • all: 16
  • RC: 0
  • I&N: 12
  • M&W: 4
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • l10n (99, -)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.6.11+dfsg-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing