Server-Side Request Forgery (SSRF) in Roundcube Webmail - CVE-2026-48843
Published: May 25, 2026 / Updated: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to make the application send requests to unintended local addresses.
The vulnerability exists due to improper access control in URL fetching logic when handling specific local address URLs. A remote attacker can supply a specially crafted URL to make the application send requests to unintended local addresses.
Affected software
Debian Linux
roundcube (Debian package)
How to mitigate CVE-2026-48843
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1