Server-Side Request Forgery (SSRF) in Roundcube Webmail - #VU132215
Published: May 25, 2026
Roundcube Webmail
Detailed vulnerability description
The vulnerability allows a remote attacker to make the application send requests to unintended local addresses.
The vulnerability exists due to improper access control in URL fetching logic when handling specific local address URLs. A remote attacker can supply a specially crafted URL to make the application send requests to unintended local addresses.