4.7
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Description
Roundcube's HTML sanitization path for message rendering allows loopback, localhost, RFC1918, link-local, and ULA URLs even when remote content loading is disabled. A remote attacker can send an HTML email that causes the victim's browser to issue requests to local or private-network services simply by opening the message preview.
Basic Information
ID
CVE-2026-9818
Source
OCD
Published
May 28, 2026 at 12:16
Affected Product
Vendor
Roundcube
Product
Webmail
Affected Versions
Roundcube Webmail 0
Roundcube Webmail 1.7.0
Roundcube Webmail 1.7.0
CWE Classification
References
- github.com /roundcube/roundcubemail/releases/tag/1.7.1
- github.com /roundcube/roundcubemail/releases/tag/1.6.16
- github.com /roundcube/roundcubemail/commit/faf867432f51ebbe100382a70a9e3c042415ee1b
- github.com /roundcube/roundcubemail/commit/7b52353653a67e6073b97d70eb94047132b78556
- advisories.orangecyberdefense.com /advisories/163