• PATCH AVAILABLE

CVE-2026-62643: ssrf and information disclosure in Roundcube Webmail

Unauthenticated attackers can cause Roundcube Webmail to fetch or leak internal resources by sending specially crafted HTML e‑mail that abuses insufficient CSS sanitization. CVE-2026-62643 affects Roundcube Webmail 1.6.0 through 1.6.16 and 1.7.0 through 1.7.1. An attacker only needs the ability to deliver a malicious HTML message to a mailbox on a vulnerable server; the flaw arises from stylesheet links in message HTML that can point at local network hosts and other internal endpoints.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
10CRITICAL
EPSS
0.0044
CWE
CWE-918
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — this is a critical, unauthenticated vulnerability (CVSS 10.0) that can trigger SSRF or data disclosure from Roundcube installations; apply the vendor fixes 1.6.17 or 1.7.2 immediately or block HTML message rendering until patched.

What is CVE-2026-62643?

Unauthenticated attackers can cause Roundcube Webmail to fetch or leak internal resources by sending specially crafted HTML e‑mail that abuses insufficient CSS sanitization. CVE-2026-62643 affects Roundcube Webmail 1.6.0 through 1.6.16 and 1.7.0 through 1.7.1. An attacker only needs the ability to deliver a malicious HTML message to a mailbox on a vulnerable server; the flaw arises from stylesheet links in message HTML that can point at local network hosts and other internal endpoints. The weakness is classified as CWE-918 (Server-Side Request Forgery).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Which versions of Roundcube Webmail are affected?

BRANCHAFFECTEDFIXED
1.x1.6.0 – before 1.6.171.6.17
1.x1.7.0 – before 1.7.21.7.2

Is CVE-2026-62643 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-62643

  1. Upgrade Roundcube Webmail to 1.6.17 or 1.7.2.
  2. If you cannot upgrade immediately, disable automatic HTML rendering or strip external stylesheet links from incoming messages.
  3. Limit Roundcube server network access to internal resources and enforce egress filtering so rendered content cannot reach sensitive hosts.
  4. Monitor webmail logs for unusual external fetches and follow vendor guidance for additional mitigations.

Frequently asked questions

Is CVE-2026-62643 being actively exploited?

There are no public reports of exploitation of CVE-2026-62643 as of 2026-09-29.

Which Roundcube Webmail versions are affected by CVE-2026-62643?

Roundcube Webmail versions 1.6.0 through 1.6.16 and 1.7.0 through 1.7.1 are affected.

Is there a patch for CVE-2026-62643?

Yes; the issue is fixed in Roundcube Webmail 1.6.17 and 1.7.2.

Does CVE-2026-62643 require authentication?

No; the vulnerability can be triggered by an unauthenticated attacker who can deliver a crafted HTML message to a Roundcube mailbox.

References