Input validation error in Roundcube Webmail - #VU147190
Published: September 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass stylesheet URL validation.
The vulnerability exists due to improper input validation in is_local_url() when validating a stylesheet URL with a trailing-dot fully qualified domain name. A remote attacker can supply a stylesheet URL containing a trailing-dot fully qualified domain name to bypass stylesheet URL validation.