VDB
GCVE-110-MAGEIA-2026-65
GCVE-110-MAGEIA-2026-65
Advisory Published
Fix pre-auth arbitrary file write via unsafe deserialization in
redis/memcache session handler, reported by y0us.
Fix bug where a password could get changed without providing the old
password, reported by flydragon777.
Fix IMAP Injection + CSRF bypass in mail search, reported by Martila
Security Research Team.
Fix remote image blocking bypass via various SVG animate attributes,
reported by nullcathedral.
Fix remote image blocking bypass via a crafted body background
attribute, reported by nullcathedral.
Fix fixed position mitigation bypass via use of !important, reported by
nullcathedral.
Fix XSS issue in a HTML attachment preview, reported by aikido_security.
Fix SSRF + Information Disclosure via stylesheet links to a local
network hosts, reported by Georgios Tsimpidas (aka Frey), Security
Researcher at https://i0.rs/.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | roundcubemail | 0 (affected), 1.6.14-1.mga9 (unaffected), 1.6.14-1.mga9 (unaffected), 0 (affected) | — |
Aliases
Browse GCVE Records
75,403 records in the GCVE database · Updated July 30, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.