This update for roundcubemail fixes the following issues:
Changes in roundcubemail:
- update to 1.6.16
+ Fix potential too long value in IMAP ID command (#10136)
+ Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [CVE-2026-48849] [bsc#1266337]
+ Security: Fix CSS injection bypass in HTML sanitizer via SVG 'animate attributeName="style"' [CVE-2026-48848] [bsc#1266336]
+ Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [CVE-2026-48842] [bsc#1266329]
+ Security: Fix SSRF bypass via specific local address URLs [CVE-2026-48843] [bsc#1266331]
+ Security: Fix bypass of remote image blocking via CSS var() [CVE-2026-48846] [bsc#1266334]
+ Security: Fix local/private URL fetch bypass when remote resources were not allowed [CVE-2026-48845] [bsc#1266333]
+ Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [CVE-2026-48847] [bsc#1266335]
+...
Read the Full Advisory- openSUSE Leap 16.0:
roundcubemail-1.6.16-bp160.1.1
* bsc#1266329
* bsc#1266331
* bsc#1266332
* bsc#1266333
* bsc#1266334
* bsc#1266335
* bsc#1266336
* bsc#1266337
References:
* https://www.suse.com/security/cve/CVE-2026-48842.html
* https://www.suse.com/security/cve/CVE-2026-48843.html
* https://www.suse.com/security/cve/CVE-2026-48844.html
* https://www.suse.com/security/cve/CVE-2026-48845.html
* https://www.suse.com/security/cve/CVE-2026-48846.html
* https://www.suse.com/security/cve/CVE-2026-48847.html
* https://www.suse.com/security/cve/CVE-2026-48848.html
* https://www.suse.com/security/cve/CVE-2026-48849.html
Get the latest Linux and open source security news straight to your inbox.