Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 528
Alerts This Week
Warning Icon 1 528

Debian Roundcube Critical Account Takeover Denial of Service Fix DSA-6391-1

debian
Calendar Grey July 19, 2026
Scroller Debian
Multiple vulnerabilities in roundcube could lead to account takeover, cross-site scripting, SSRF bypass, and information disclosure. Upgrade recommended.
Multiple vulnerabilities were discovered in roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in account takeover, cross-site scripting, SSRF ...

Summary

For the stable distribution (trixie), these problems have been fixed in
version 1.6.17+dfsg-0+deb13u1.

We recommend that you upgrade your roundcube packages.

For the detailed security status of roundcube please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/roundcube

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: roundcube
CVE ID: CVE-2026-54432 CVE-2026-54433 CVE-2026-62641 CVE-2026-62642

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.