Description
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4480-1 | roundcube security update |
Debian DSA |
DSA-6137-1 | roundcube security update |
References
History
Mon, 09 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Feb 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage. | |
| First Time appeared |
Roundcube
Roundcube webmail |
|
| Weaknesses | CWE-420 | |
| CPEs | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roundcube
Roundcube webmail |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-09T15:05:40.859Z
Reserved: 2026-02-09T08:14:10.021Z
Link: CVE-2026-25916
Updated: 2026-02-09T15:00:36.368Z
Status : Awaiting Analysis
Published: 2026-02-09T09:16:34.193
Modified: 2026-02-09T16:08:35.290
Link: CVE-2026-25916
No data.
OpenCVE Enrichment
Updated: 2026-02-10T12:23:46Z
Weaknesses
Debian DLA
Debian DSA