CVE Vulnerabilities

CVE-2026-25916

Unprotected Alternate Channel

Published: Feb 09, 2026 | Modified: Feb 09, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when Block remote images is used, does not block SVG feImage.

Weakness

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Affected Software

NameVendorStart VersionEnd Version
RoundcubeUbuntuupstream*

Potential Mitigations

References