Alerts This Week
Warning Icon 1 717
Alerts This Week
Warning Icon 1 717

Debian Roundcube Important DSA-6196-1 Multiple Vulnerabilities

debian
Calendar Grey April 4, 2026
Debian Logo
Roundcube webmail faces multiple vulnerabilities leading to serious access and disclosure threat. Upgrade recommended for security.
Multiple vulnerabilities were discovered in roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in information disclosure, IMAP injection, CSRF ...

Summary

For the oldstable distribution (bookworm), these problems have been fixed
in version 1.6.5+dfsg-1+deb12u8.

For the stable distribution (trixie), these problems have been fixed in
version 1.6.15+dfsg-0+deb13u1.

We recommend that you upgrade your roundcube packages.

For the detailed security status of roundcube please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/roundcube

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: roundcube
CVE ID: CVE-2026-35537 CVE-2026-35538 CVE-2026-35539 CVE-2026-35540

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here