Server-Side Request Forgery (SSRF) in Roundcube Webmail - #VU132216

 

Server-Side Request Forgery (SSRF) in Roundcube Webmail - #VU132216

Published: May 25, 2026


Vulnerability identifier: #VU132216
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Roundcube
Affected software:
Roundcube Webmail

Detailed vulnerability description

The vulnerability allows a remote attacker to make the application fetch local or private URLs despite restrictions.

The vulnerability exists due to improper access control in remote resource fetching when handling local or private URLs while remote resources are disallowed. A remote attacker can supply a specially crafted URL to make the application fetch local or private URLs despite restrictions.

The issue occurs when remote resources are not allowed.


Remediation

Install security update from vendor's website.

Sources