Description
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.
Published: 2026-07-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Roundcube Webmail TNEF decoder, present before version 1.6.17 and before 1.7.2, can be forced into denial‑of‑service payload. The issue stems from a resource exhaustion scenario caused by an oversized data size in the decoder, leading to service slowdown or crash. This weakness is classified as CWE‑770, reflecting an out‑of‑memory condition that disrupts availability.

Affected Systems

Systems running Roundcube Webmail before 1.6.17 for the 1.6.x branch or before 1.7.2 for the 1.7.x branch are at risk. Updated versions 1.6.17 and later, and 1.7.2 and later, contain the fix.

Risk and Exploitability

The CVSS score is 4.3, and the EPSS score is less than 1%, which indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog and requires an attacker to submit a malicious email through the webmail interface to trigger the DoS. Based on the description, the likely attack vector is via a crafted attachment containing a compressed‑RTF payload that the TNEF decoder processes, leading to resource exhaustion. Because it does not grant remote code execution or elevate privileges, the potential damage is limited to service disruption for users or administrators on the affected host.

Generated by OpenCVE AI on July 31, 2026 at 10:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Roundcube Webmail to version 1.6.17 or later; for 1.7.x, upgrade to 1.7.2 or later, which contain the fixed TNEF decoder.
  • If an upgrade cannot be performed immediately, disable or remove the TNEF decoding functionality in the Roundcube configuration to prevent large compressed‑RTF files from being processed, thereby reducing the risk of resource exhaustion.
  • Enforce additional attachment size restrictions at the web server or mail transfer agent level to block large compressed‑RTF files before they reach Roundcube, thereby reducing the likelihood of resource exhaustion.

Generated by OpenCVE AI on July 31, 2026 at 10:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4693-1 roundcube security update
Debian DSA Debian DSA DSA-6391-1 roundcube security update
History

Fri, 31 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via TNEF Decoder Resource Exhaustion in Roundcube Webmail

Sat, 25 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via TNEF Decoder Resource Exhaustion in Roundcube Webmail

Fri, 24 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Roundcube Webmail TNEF Decoder DoS via Crafted Compressed‑RTF Payload

Mon, 20 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Roundcube Webmail TNEF Decoder DoS via Crafted Compressed‑RTF Payload

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.
First Time appeared Roundcube
Roundcube webmail
Weaknesses CWE-770
CPEs cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
Vendors & Products Roundcube
Roundcube webmail
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}


Subscriptions

Roundcube Webmail
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-14T17:27:50.013Z

Reserved: 2026-07-14T15:46:28.729Z

Link: CVE-2026-62641

cve-icon Vulnrichment

Updated: 2026-07-14T17:27:37.976Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:15:06Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling