Description
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Published: 2026-05-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Roundcube Webmail’s HTML sanitization incorrectly permits loopback, localhost, RFC1918, link‑local, and ULA URLs even when remote content loading is disabled. A remote attacker can send a crafted HTML email that, when the recipient opens the preview, causes the victim’s browser to request services on private or local networks. This behavior can lead to information disclosure and internal network discovery, and could enable unintended actions on local services by exploiting the outbound request capability. The weakness stems from improper validation of outbound URLs (CWE‑184).

Affected Systems

All installations of Roundcube Webmail older than version 1.6.16 or 1.7.1 are affected. The vendor recommends upgrading to Roundcube 1.6.16 or 1.7.1 to remove the flaw.

Risk and Exploitability

The CVSS score of 4.7 indicates a moderate risk. No EPSS score is available and the vulnerability is not listed in CISA KEV. Exploitation requires only that a victim opens a maliciously crafted email; no privileged server access or code execution is necessary. The attacker can induce outbound requests to private or local addresses, which can aid reconnaissance or trigger internal services, making the attack feasible in typical user scenarios. The likely attack vector is the victim opening the preview of the affected email. Given its moderate severity and the lack of a widespread public exploit, the overall risk is considered moderate but non‑negligible for environments with sensitive internal services.

Generated by OpenCVE AI on May 28, 2026 at 13:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Roundcube Webmail to version 1.6.16 or 1.7.1 as soon as possible.
  • If a patch cannot be applied immediately, block outbound connections from the webmail service to RFC1918, link‑local, and ULA IP ranges using firewall rules on the server.
  • Configure Roundcube or a complementary proxy to strip or deny local and private URLs from incoming emails, and monitor outbound traffic originating from the webmail application for anomalous requests.

Generated by OpenCVE AI on May 28, 2026 at 13:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References

No reference.

History

Thu, 28 May 2026 17:30:00 +0000


Thu, 28 May 2026 17:00:00 +0000

Type Values Removed Values Added
Description Roundcube's HTML sanitization path for message rendering allows loopback, localhost, RFC1918, link-local, and ULA URLs even when remote content loading is disabled. A remote attacker can send an HTML email that causes the victim's browser to issue requests to local or private-network services simply by opening the message preview. This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CPEs cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*

Thu, 28 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 May 2026 12:45:00 +0000

Type Values Removed Values Added
Description Roundcube's HTML sanitization path for message rendering allows loopback, localhost, RFC1918, link-local, and ULA URLs even when remote content loading is disabled. A remote attacker can send an HTML email that causes the victim's browser to issue requests to local or private-network services simply by opening the message preview.
Title Roundcube Local/Private URL Fetch Bypass
First Time appeared Roundcube
Roundcube webmail
Weaknesses CWE-184
CPEs cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
Vendors & Products Roundcube
Roundcube webmail
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}


Subscriptions

Roundcube Webmail
cve-icon MITRE

Status: REJECTED

Assigner: OCD

Published:

Updated: 2026-05-28T16:35:38.661Z

Reserved: 2026-05-28T10:37:45.625Z

Link: CVE-2026-9818

cve-icon Vulnrichment

Updated: 2026-05-28T13:24:14.064Z

cve-icon NVD

Status : Rejected

Published: 2026-05-28T13:16:25.440

Modified: 2026-05-28T17:16:36.090

Link: CVE-2026-9818

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T16:30:15Z

Weaknesses

No weakness.