🛡️ openSUSE-SU-2026:20586-1 — roundcubemail (CVE-2026-35537)
Description
Security update for roundcubemail
This update for roundcubemail fixes the following issues:
Changes in roundcubemail:
- update to 1.6.15
This is a security update to the stable version 1.6 of Roundcube Webmail.
It provides fixes to some regressions introduced in the previous release
as well a recently reported security vulnerability:
SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke, reported by class_nzm.
This version is considered stable and we recommend to update all productive
installations of Roundcube 1.6.x with it. Please do backup your data before updating!
+ Fix regression where mail search would fail on non-ascii search criteria (#10121)
+ Fix regression where some data url images could get ignored/lost (#10128)
+ Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke (bsc#1261157)
- update to 1.6.14
This is a security update to the stable version 1.6 of Roundcube Webmail.
+ Fix Postgres connection using IPv6 address (#10104)
+ Security: Fix pre-auth arbitrary file write via unsafe deserialization in redis/memcache session handler
(bsc#1261488, CVE-2026-35537)
+ Security: Fix bug where a password could get changed without providing the old password
+ Security: Fix IMAP Injection + CSRF bypass in mail search
+ Security: Fix remote image blocking bypass via various SVG animate attributes
+ Security: Fix remote image blocking bypass via a crafted body background attribute
+ Security: Fix fixed position mitigation bypass via use of !important
+ Security: Fix XSS issue in a HTML attachment preview
+ Security: Fix SSRF + Information Disclosure via stylesheet links to a local network hosts
Affected software
openSUSE-SU-2026:20586-1 is recorded against 1 package.
- roundcubemail (fixed in 1.6.15-bp160.1.1)
Timeline and source
Published on 17 April 2026 and last revised on 22 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| roundcubemail | — | 1.6.15-bp160.1.1 |
References
Similar Threats
- Unknown MGASA-2026-0194
- Unknown openSUSE-SU-2026:10869-1
- Unknown MGASA-2026-0089
- Unknown MGASA-2026-0065
- Unknown MGASA-2025-0332
Free Vulnerability Check
Is your site affected by openSUSE-SU-2026:20586-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2026:20586-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.