{"id":"openSUSE-SU-2026:20852-1","summary":"Security update for roundcubemail","details":"This update for roundcubemail fixes the following issues:\n\nChanges in roundcubemail:\n\n- update to 1.6.16\n  + Fix potential too long value in IMAP ID command (#10136)\n  + Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [CVE-2026-48849] [bsc#1266337]\n  + Security: Fix CSS injection bypass in HTML sanitizer via SVG 'animate attributeName=\"style\"' [CVE-2026-48848] [bsc#1266336]\n  + Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [CVE-2026-48842] [bsc#1266329]\n  + Security: Fix SSRF bypass via specific local address URLs [CVE-2026-48843] [bsc#1266331]\n  + Security: Fix bypass of remote image blocking via CSS var() [CVE-2026-48846] [bsc#1266334]\n  + Security: Fix local/private URL fetch bypass when remote resources were not allowed [CVE-2026-48845] [bsc#1266333]\n  + Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [CVE-2026-48847] [bsc#1266335]\n  + Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option [CVE-2026-48844] [bsc#1266332]\n","modified":"2026-06-02T18:24:31.599657638Z","published":"2026-05-31T10:25:53Z","related":["CVE-2026-48842","CVE-2026-48843","CVE-2026-48844","CVE-2026-48845","CVE-2026-48846","CVE-2026-48847","CVE-2026-48848","CVE-2026-48849"],"upstream":["CVE-2026-48842","CVE-2026-48843","CVE-2026-48844","CVE-2026-48845","CVE-2026-48846","CVE-2026-48847","CVE-2026-48848","CVE-2026-48849"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266329"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266331"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266332"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266333"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266334"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266335"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266336"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266337"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48842"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48843"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48844"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48845"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48846"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48847"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48848"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48849"}],"schema_version":"1.7.5"}