Roundcube SSRF flaw lets incoming emails probe internal networks via mail server
A security researcher reproduced a server-side request forgery (SSRF) vulnerability in Roundcube webmail by setting up the affected version on an isolated lab environment. The flaw, patched in Roundcube release 1.6.17 in July 2026, allows a specially crafted HTML email to make the mail server silently fetch internal network addresses without user interaction. NIST scored the vulnerability a perfect 10.0, while MITRE assigned it a 7.2, reflecting differing assessments of exploitability. The root cause lies in Roundcube's CSS sanitization feature, where the server itself fetches external stylesheets referenced in emails before passing them to the browser. The researcher confirmed the attack by capturing the outbound request in server logs, demonstrating that the existing local-URL check could be bypassed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in