Fiche vulnérabilité
CVE-2026-35540 : faille moyenne roundcube webmail (CVSS 6.5)
Description
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.
En bref
- Sévérité
- Moyenne (CVSS 6.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 3 avr. 2026
- Dernière mise à jour
- 24 juil. 2026
Produits concernés
- roundcube webmail
Références
- Fiche CVE-2026-35540 sur le NVD (NIST)
- github.com/roundcube/roundcubemail/commit/27ec6cc9cb25e1e…
- github.com/roundcube/roundcubemail/commit/579b68eff90650a…
- github.com/roundcube/roundcubemail/releases/tag/1.6.14
- github.com/roundcube/roundcubemail/releases/tag/1.7-rc5
- roundcube.net/news/2026/03/18/security…