Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

openSUSE 1.6.15 Roundcube Moderate Security Update 2026-0144-1

opensuse
Calendar Grey April 20, 2026
Dist Opensuse Esm H88
openSUSE Roundcube Webmail update resolves security risks and bug fixes with emphasis on critical image loading issues.
An update that solves one vulnerability and has one errata is now available.

Description

This update for roundcubemail fixes the following issues:

- update to 1.6.15 This is a security update to the stable version 1.6 of

Roundcube Webmail. It provides fixes to some regressions introduced in

the previous release as well a recently reported security vulnerability:

SVG Animate FUNCIRI Attribute Bypass \u2014 Remote Image Loading via

fill/filter/stroke, reported by class_nzm. This version is considered

stable and we recommend to update all productive installations of

Roundcube 1.6.x with it. Please do backup your data before updating!

+ Fix regression where mail search would fail on non-ascii search

criteria (#10121)

+ Fix regression where some data url images could get ignored/lost

(#10128)

+ Fix SVG Animate FUNCIRI Attribute Bypass \u2014 Remote Image Loading via

fill/filter/stroke (boo#1261157)

- update to 1.6.14 This is a security update to the stable version 1.6 of

Roundcube Webmail.

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2026-144=1

Package List

- openSUSE Backports SLE-15-SP6 (noarch):

roundcubemail-1.6.15-bp156.2.15.1

References

https://www.suse.com/security/cve/CVE-2026-35537.html

https://bugzilla.suse.com/1261157

https://bugzilla.suse.com/1261488

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:0144-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP6 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here