Home

Description

Roundcube's HTML sanitization path for message rendering allows loopback, localhost, RFC1918, link-local, and ULA URLs even when remote content loading is disabled. A remote attacker can send an HTML email that causes the victim's browser to issue requests to local or private-network services simply by opening the message preview.

PUBLISHED Reserved 2026-05-28 | Published 2026-05-28 | Updated 2026-05-28 | Assigner OCD




MEDIUM: 4.7CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Problem types

CWE-184 Incomplete list of disallowed inputs

Product status

Default status
unaffected

Any version before 1.6.16
affected

1.7.0 (git) before 1.7.1
affected

Credits

Guillaume Meunier from Orange Cyberdefense CERT VOC Team finder

References

github.com/roundcube/roundcubemail/releases/tag/1.7.1 patch

github.com/roundcube/roundcubemail/releases/tag/1.6.16 patch

github.com/...ommit/faf867432f51ebbe100382a70a9e3c042415ee1b patch

github.com/...ommit/7b52353653a67e6073b97d70eb94047132b78556 patch

advisories.orangecyberdefense.com/advisories/163 third-party-advisory

cve.org (CVE-2026-9818)

nvd.nist.gov (CVE-2026-9818)

Download JSON