Server-Side Request Forgery (SSRF) in Roundcube Webmail - CVE-2026-48845
Published: May 25, 2026 / Updated: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to make the application fetch local or private URLs despite restrictions.
The vulnerability exists due to improper access control in remote resource fetching when handling local or private URLs while remote resources are disallowed. A remote attacker can supply a specially crafted URL to make the application fetch local or private URLs despite restrictions.
The issue occurs when remote resources are not allowed.
Affected software
Debian Linux
roundcube (Debian package)
How to mitigate CVE-2026-48845
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1