Debian Package Tracker
Register | Log in
Subscribe

roundcube

skinnable AJAX based webmail solution for IMAP servers - metapackage

Choose email to subscribe with

general
  • source: roundcube (main)
  • version: 1.6.17+dfsg-1
  • maintainer: Debian Roundcube Maintainers (archive) (DMD)
  • uploaders: Vincent Bernat [DMD] – Sandro Knauß [DMD] – Guilhem Moulin [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.4.15+dfsg.1-1+deb11u4
  • o-o-sec: 1.4.15+dfsg.1-1+deb11u9
  • o-o-p-u: 1.4.15+dfsg.1-1+deb11u4
  • oldstable: 1.6.5+dfsg-1+deb12u9
  • old-sec: 1.6.5+dfsg-1+deb12u9
  • old-p-u: 1.6.5+dfsg-1+deb12u9
  • stable: 1.6.16+dfsg-0+deb13u1
  • stable-sec: 1.6.17+dfsg-0+deb13u1
  • testing: 1.6.17+dfsg-1
  • unstable: 1.6.17+dfsg-1
versioned links
  • 1.4.15+dfsg.1-1+deb11u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.15+dfsg.1-1+deb11u9: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.5+dfsg-1+deb12u9: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.16+dfsg-0+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.17+dfsg-0+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.17+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • roundcube (5 bugs: 0, 5, 0, 0)
  • roundcube-core (11 bugs: 0, 7, 4, 0)
  • roundcube-mysql
  • roundcube-pgsql
  • roundcube-plugins
  • roundcube-sqlite3
action needed
Marked for autoremoval on 17 August due to erlang: #1141414 high
Version 1.6.17+dfsg-1 of roundcube is marked for autoremoval from testing on Mon 17 Aug 2026. It depends (transitively) on erlang, affected by #1141414. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-06-28 Last update: 2026-07-20 01:33
A new upstream version is available: 1.7.2 high
A new upstream version 1.7.2 is available, you should consider packaging it.
Created: 2026-05-25 Last update: 2026-07-19 23:00
7 security issues in bullseye high

There are 7 open security issues in bullseye.

6 important issues:
  • CVE-2026-54432: Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.
  • CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).
  • CVE-2026-62641: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.
  • CVE-2026-62642: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
  • CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.
  • CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
1 ignored issue:
  • CVE-2019-15237: Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
Created: 2026-07-05 Last update: 2026-07-19 20:30
6 security issues in bookworm high

There are 6 open security issues in bookworm.

6 important issues:
  • CVE-2026-54432: Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.
  • CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).
  • CVE-2026-62641: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.
  • CVE-2026-62642: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
  • CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.
  • CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Created: 2026-07-05 Last update: 2026-07-19 20:30
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2026-06-02 Last update: 2026-07-20 01:31
1 new commit since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 7acd2a6367f9cba29673c8f9ccdb0e4d7f303185
Author: Guilhem Moulin <guilhem@debian.org>
Date:   Wed Jul 15 01:20:05 2026 +0200

    d/changelog: Retroactively mention CVE-2026-62641 to -62644 for 1.6.17+dfsg-1.
    
    Gbp-Dch: Ignore
Created: 2026-07-15 Last update: 2026-07-15 00:18
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2026-07-06 Last update: 2026-07-06 04:48
debian/patches: 1 patch to forward upstream low

Among the 26 debian patches available in version 1.6.17+dfsg-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2024-12-21 Last update: 2026-07-06 11:32
Issues found with some translations low

Automatic checks made by the Debian l10n team found some issues with the translations contained in this package. You should check the l10n status report for more information.

Issues can be things such as missing translations, problematic translated strings, outdated PO files, unknown languages, etc.

Created: 2026-02-09 Last update: 2026-02-09 12:19
news
[rss feed]
  • [2026-07-19] Accepted roundcube 1.6.17+dfsg-0+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-07-08] roundcube 1.6.17+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-05] Accepted roundcube 1.6.17+dfsg-1 (source) into unstable (Guilhem Moulin)
  • [2026-05-29] roundcube 1.6.16+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-28] Accepted roundcube 1.6.5+dfsg-1+deb12u9 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-05-28] Accepted roundcube 1.6.16+dfsg-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-05-28] Accepted roundcube 1.4.15+dfsg.1-1+deb11u9 (source) into oldoldstable-security (Guilhem Moulin)
  • [2026-05-27] Accepted roundcube 1.6.16+dfsg-0+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-05-27] Accepted roundcube 1.6.5+dfsg-1+deb12u9 (source) into oldstable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-05-24] Accepted roundcube 1.6.16+dfsg-1 (source) into unstable (Guilhem Moulin)
  • [2026-05-11] roundcube REMOVED from testing (Debian testing watch)
  • [2026-04-06] Accepted roundcube 1.6.5+dfsg-1+deb12u8 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-04-06] Accepted roundcube 1.6.15+dfsg-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-04-04] Accepted roundcube 1.6.15+dfsg-0+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-04-04] Accepted roundcube 1.6.5+dfsg-1+deb12u8 (source) into oldstable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-04-02] roundcube 1.6.15+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-30] Accepted roundcube 1.4.15+dfsg.1-1+deb11u8 (source) into oldoldstable-security (Guilhem Moulin)
  • [2026-03-30] Accepted roundcube 1.6.15+dfsg-1 (source) into unstable (Guilhem Moulin)
  • [2026-03-24] roundcube 1.6.14+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-20] Accepted roundcube 1.6.14+dfsg-1 (source) into unstable (Guilhem Moulin)
  • [2026-02-21] Accepted roundcube 1.6.5+dfsg-1+deb12u7 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-02-19] Accepted roundcube 1.6.13+dfsg-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-02-17] Accepted roundcube 1.4.15+dfsg.1-1+deb11u7 (source) into oldoldstable-security (Guilhem Moulin)
  • [2026-02-17] Accepted roundcube 1.6.5+dfsg-1+deb12u7 (source) into oldstable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-02-17] Accepted roundcube 1.6.13+dfsg-0+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2026-02-11] roundcube 1.6.13+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-08] Accepted roundcube 1.6.13+dfsg-1 (source) into unstable (Guilhem Moulin)
  • [2025-12-20] Accepted roundcube 1.6.5+dfsg-1+deb12u6 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2025-12-20] Accepted roundcube 1.6.12+dfsg-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Guilhem Moulin)
  • [2025-12-19] Accepted roundcube 1.6.12+dfsg-0+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Guilhem Moulin)
  • 1
  • 2
bugs [bug history graph]
  • all: 16
  • RC: 0
  • I&N: 12
  • M&W: 4
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • l10n (99, -)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.6.11+dfsg-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing