Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE Leap 16.0 roundcubemail Important Remote Image Fix 2026-20586-1

opensuse
Calendar Grey April 21, 2026
Dist Opensuse Esm H88
A critical openSUSE security update for roundcubemail addresses a remote image bypass issue and includes bug fixes.
An update that solves one vulnerability and has 2 bug fixes can now be installed.

Description

This update for roundcubemail fixes the following issues:

Changes in roundcubemail:

- update to 1.6.15

This is a security update to the stable version 1.6 of Roundcube Webmail.

It provides fixes to some regressions introduced in the previous release

as well a recently reported security vulnerability:

SVG Animate FUNCIRI Attribute Bypass \u2014 Remote Image Loading via fill/filter/stroke, reported by class_nzm.

This version is considered stable and we recommend to update all productive

installations of Roundcube 1.6.x with it. Please do backup your data before updating!

+ Fix regression where mail search would fail on non-ascii search criteria (#10121)

+ Fix regression where some data url images could get ignored/lost (#10128)

+ Fix SVG Animate FUNCIRI Attribute Bypass \u2014 Remote Image Loading via fill/filter/stroke (bsc#1261157)

- update to 1.6.14

This is a security update to the stable version 1.6 of Roundcube Webmail.

+ Fix Postgres connection using...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

roundcubemail-1.6.15-bp160.1.1

References

* bsc#1261157

* bsc#1261488

References:

* https://www.suse.com/security/cve/CVE-2026-35537.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20586-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here