CVE-2026-62643
published 2026-07-14CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or…
PriorityP352critical10CVSS 3.1
AVNACLPRNUINSCCHIHAN
EPSS
0.44%
36.6th percentile
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| roundcube | webmail | >= 1.6.0 < 1.6.17 | 1.6.17 |
| roundcube | webmail | >= 1.7.0 < 1.7.2 | 1.7.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if styleshee
ghsa_unreviewed·2026-08-17·CVSS 6.5
CVE-2026-75006 [MEDIUM] CWE-918 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if styleshee
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.
VulDB
Roundcube Webmail up to 1.6.16/1.7.1 CSS server-side request forgery (WID-SEC-2026-2207 / CNNVD-2026-99036270)
vuldb·2026-07-16·CVSS 7.2
CVE-2026-62643 [HIGH] Roundcube Webmail up to 1.6.16/1.7.1 CSS server-side request forgery (WID-SEC-2026-2207 / CNNVD-2026-99036270)
A vulnerability was found in Roundcube Webmail up to 1.6.16/1.7.1. It has been declared as problematic. This vulnerability affects unknown code of the component CSS. Executing a manipulation can lead to server-side request forgery.
This vulnerability is registered as CVE-2026-62643. It is possible to launch the attack remotely. No exploit is available.
GHSA
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if styleshee
ghsa_unreviewed·2026-07-14·CVSS 6.5
CVE-2026-62643 [MEDIUM] CWE-918 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if styleshee
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-62643 roundcubemail: Roundcube Webmail: Server-Side Request Forgery via insufficient CSS sanitization
bugzilla·2026-07-14·CVSS 6.5
CVE-2026-62643 [MEDIUM] CVE-2026-62643 roundcubemail: Roundcube Webmail: Server-Side Request Forgery via insufficient CSS sanitization
CVE-2026-62643 roundcubemail: Roundcube Webmail: Server-Side Request Forgery via insufficient CSS sanitization
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.
Bugzilla
CVE-2026-62643 roundcubemail: Roundcube Webmail: Server-Side Request Forgery via insufficient CSS sanitization [epel-all]
bugzilla·2026-07-14·CVSS 6.5
CVE-2026-62643 [MEDIUM] CVE-2026-62643 roundcubemail: Roundcube Webmail: Server-Side Request Forgery via insufficient CSS sanitization [epel-all]
CVE-2026-62643 roundcubemail: Roundcube Webmail: Server-Side Request Forgery via insufficient CSS sanitization [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.
Bugzilla
CVE-2026-62643 roundcubemail: Roundcube Webmail: Server-Side Request Forgery via insufficient CSS sanitization [fedora-all]
bugzilla·2026-07-14·CVSS 6.5
CVE-2026-62643 [MEDIUM] CVE-2026-62643 roundcubemail: Roundcube Webmail: Server-Side Request Forgery via insufficient CSS sanitization [fedora-all]
CVE-2026-62643 roundcubemail: Roundcube Webmail: Server-Side Request Forgery via insufficient CSS sanitization [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.
https://github.com/roundcube/roundcubemail/commit/294c7da6e7284166f040cef8607b677d459e0786https://github.com/roundcube/roundcubemail/commit/6d69e094d55d3a9a84dfb36edf6ca985311f0c1chttps://github.com/roundcube/roundcubemail/releases/tag/1.6.17https://github.com/roundcube/roundcubemail/releases/tag/1.7.2https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2
2026-07-14
Published