Server-Side Request Forgery (SSRF) in Roundcube Webmail - #VU132216
Published: May 25, 2026
Roundcube Webmail
Detailed vulnerability description
The vulnerability allows a remote attacker to make the application fetch local or private URLs despite restrictions.
The vulnerability exists due to improper access control in remote resource fetching when handling local or private URLs while remote resources are disallowed. A remote attacker can supply a specially crafted URL to make the application fetch local or private URLs despite restrictions.
The issue occurs when remote resources are not allowed.