You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"details": "An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.",
Copy file name to clipboardExpand all lines: advisories/github-reviewed/2026/04/GHSA-rxj3-rrwm-pj4r/GHSA-rxj3-rrwm-pj4r.json
+29-4Lines changed: 29 additions & 4 deletions
Original file line number
Diff line number
Diff line change
@@ -1,19 +1,40 @@
1
1
{
2
2
"schema_version": "1.4.0",
3
3
"id": "GHSA-rxj3-rrwm-pj4r",
4
-
"modified": "2026-04-03T06:31:32Z",
4
+
"modified": "2026-04-04T06:50:14Z",
5
5
"published": "2026-04-03T06:31:32Z",
6
6
"aliases": [
7
7
"CVE-2026-35537"
8
8
],
9
+
"summary": "Roundcube Webmail: Unsafe deserialization in the redis/memcache session handler",
9
10
"details": "An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.",
Copy file name to clipboardExpand all lines: advisories/github-reviewed/2026/04/GHSA-x4q5-8j5g-hpjc/GHSA-x4q5-8j5g-hpjc.json
+29-4Lines changed: 29 additions & 4 deletions
Original file line number
Diff line number
Diff line change
@@ -1,19 +1,40 @@
1
1
{
2
2
"schema_version": "1.4.0",
3
3
"id": "GHSA-x4q5-8j5g-hpjc",
4
-
"modified": "2026-04-03T06:31:32Z",
4
+
"modified": "2026-04-04T06:50:55Z",
5
5
"published": "2026-04-03T06:31:32Z",
6
6
"aliases": [
7
7
"CVE-2026-35539"
8
8
],
9
+
"summary": "Roundcube Webmail: Insufficient HTML attachment sanitization in preview mode",
9
10
"details": "An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.",
0 commit comments