Security update for roundcubemail

This is a security update to the LTS version 1.6 of Roundcube Webmail.
It provides fixes to recently reported security vulnerabilities:

+ Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [CVE-2026-48849] [bsc#1266337]
+ Security: Fix CSS injection bypass in HTML sanitizer via SVG [CVE-2026-48848] [bsc#1266336]
+ Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [CVE-2026-48842] [bsc#1266329]
+ Security: Fix SSRF bypass via specific local address URLs [CVE-2026-48843] [bsc#1266331]
+ Security: Fix bypass of remote image blocking via CSS var() [CVE-2026-48846] [bsc#1266334]
+ Security: Fix local/private URL fetch bypass when remote resources were not allowed [CVE-2026-48845] [bsc#1266333]
+ Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [CVE-2026-48847] [bsc#1266335]
+ Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option [CVE-2026-48844] [bsc#1266332]

This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating!

Fixed bugs
bnc#1266329
VUL-0: CVE-2026-48842: roundcubemail: pre-authentication SQL injection in the `virtuser_query` plugin via a `preg_replace()` backslash escape bypass
bnc#1266331
VUL-0: CVE-2026-48843: roundcubemail: insufficient CSS sanitization in HTML e-mail messages may lead to SSRF or information disclosure
bnc#1266332
VUL-0: CVE-2026-48844: roundcubemail: insecure code evaluation logic in LDAP the autovalues option can lead to code injection
bnc#1266333
VUL-0: CVE-2026-48845: roundcubemail: improper remote image blocking for URLs pointing to local/private destinations can lead to information disclosure or privilege escalation via a text/html email message
bnc#1266334
VUL-0: CVE-2026-48846: roundcubemail: remote image blocking feature can be bypassed via a crafted CSS `var()` value in an e-mail message
bnc#1266335
VUL-0: CVE-2026-48847: roundcubemail: pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass
bnc#1266336
VUL-0: CVE-2026-48848: roundcubemail: insufficient HTML sanitization can lead to CSS injection via an SVG document that has an animate element with the `attributeName` attribute
bnc#1266337
VUL-0: CVE-2026-48849: roundcubemail: unsanitized subject field in the draft restored value can lead to stored XSS and HTML/CSS injection on shared mailboxes
bnc#1266329
VUL-0: CVE-2026-48842: roundcubemail: pre-authentication SQL injection in the `virtuser_query` plugin via a `preg_replace()` backslash escape bypass
bnc#1266331
VUL-0: CVE-2026-48843: roundcubemail: insufficient CSS sanitization in HTML e-mail messages may lead to SSRF or information disclosure
bnc#1266332
VUL-0: CVE-2026-48844: roundcubemail: insecure code evaluation logic in LDAP the autovalues option can lead to code injection
bnc#1266333
VUL-0: CVE-2026-48845: roundcubemail: improper remote image blocking for URLs pointing to local/private destinations can lead to information disclosure or privilege escalation via a text/html email message
bnc#1266334
VUL-0: CVE-2026-48846: roundcubemail: remote image blocking feature can be bypassed via a crafted CSS `var()` value in an e-mail message
bnc#1266335
VUL-0: CVE-2026-48847: roundcubemail: pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass
bnc#1266336
VUL-0: CVE-2026-48848: roundcubemail: insufficient HTML sanitization can lead to CSS injection via an SVG document that has an animate element with the `attributeName` attribute
bnc#1266337
VUL-0: CVE-2026-48849: roundcubemail: unsanitized subject field in the draft restored value can lead to stored XSS and HTML/CSS injection on shared mailboxes
Selected Binaries
openSUSE Build Service is sponsored by