VDB

GCVE-110-MAGEIA-2026-65

GCVE-110-MAGEIA-2026-65
Advisory Published
Vulnetix · Advisory published March 24, 2026
Fix pre-auth arbitrary file write via unsafe deserialization in redis/memcache session handler, reported by y0us. Fix bug where a password could get changed without providing the old password, reported by flydragon777. Fix IMAP Injection + CSRF bypass in mail search, reported by Martila Security Research Team. Fix remote image blocking bypass via various SVG animate attributes, reported by nullcathedral. Fix remote image blocking bypass via a crafted body background attribute, reported by nullcathedral. Fix fixed position mitigation bypass via use of !important, reported by nullcathedral. Fix XSS issue in a HTML attachment preview, reported by aikido_security. Fix SSRF + Information Disclosure via stylesheet links to a local network hosts, reported by Georgios Tsimpidas (aka Frey), Security Researcher at https://i0.rs/.

Affected Products

VendorProductVersionsPlatforms
Mageiaroundcubemail0 (affected), 1.6.14-1.mga9 (unaffected), 1.6.14-1.mga9 (unaffected), 0 (affected)

Browse GCVE Records

75,403 records in the GCVE database · Updated July 30, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›