Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Debian 11 Roundcube Information Disclosure Update DLA-4480-1 CVE-2026-25916

debian lts
Calendar Grey February 17, 2026
Dist Debian Esm H88
Roundcube security patch for Debian LTS resolves information disclosure and privilege escalation issues. Upgrade now!
Vulnerabilities were discovered in Roundcube, a skinnable AJAX based webmail solution for IMAP servers, which might lead to information disclosure or privilege escalation

Summary

CVE-2026-25916

NULL CATHEDRAL discovered that the HTML sanitizer doesn't treat SVG
`` as an image source. This allows attackers to
bypass remote image blocking to track email open action or
potentially bypass access control.

CVE-2026-26079

CERT Polska discovered that CSS code in text/html emails were
insufficiently sanitized, allowing an attacker to inject malicious
stylesheet rules.

For Debian 11 bullseye, these problems have been fixed in version
1.4.15+dfsg.1-1+deb11u7.

We recommend that you upgrade your roundcube packages.

For the detailed security status of roundcube please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/roundcube

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
important
Lowest
Low
Medium
High
Critical

Package: roundcube
Version: 1.4.15+dfsg.1-1+deb11u7
CVE ID: CVE-2026-25916 CVE-2026-26079
Debian Bug: 1127447

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here