Hi Guilhem, On Thu, Jul 16, 2026 at 08:42:02PM +0200, Salvatore Bonaccorso wrote: > Hi Guilhem, > > On Wed, Jul 15, 2026 at 01:37:29AM +0200, Guilhem Moulin wrote: > > Hi, > > > > On Sun, 05 Jul 2026 at 17:04:05 +0200, Guilhem Moulin wrote: > > > 1. Infinite loop in TNEF (winmail.dat) decoder > > > > > > https://github.com/roundcube/roundcubemail/commit/a007321346380136b3de2bd75b486b04f63c0d38 > > > > > > https://github.com/roundcube/roundcubemail/commit/132ac8dd5a55c8466be12de1daf84355697ffa89 > > > > CVE-2026-62642 was assigned for this issue. > > > > > 2. Various vulnerabilities in the password plugin using > > > session-injected username > > > > > > https://github.com/roundcube/roundcubemail/commit/83150ce04d689a70f92d511bcae40adba8d55476 > > > > > > https://github.com/roundcube/roundcubemail/commit/5cdc6a48b40beabff7f0bf5d9035f4491e877e4c > > > > CVE-2026-62644 was assigned for this issue. > > > > > 3. CVE-2026-54432: Stored XSS via unescaped attachment MIME type on > > > the attachment-validation warning page > > > > > > https://github.com/roundcube/roundcubemail/commit/a3a4482cc9bd5569107e4393d32abb157cb2a568 > > > 4. SSRF bypass via specific local address URLs > > > > > > https://github.com/roundcube/roundcubemail/commit/294c7da6e7284166f040cef8607b677d459e0786 > > > > CVE-2026-62643 was assigned for this issue. > > > > > 5. CVE-2026-54433: Zero-click stored XSS in plain-text rendering > > > > > > https://github.com/roundcube/roundcubemail/commit/63e42e233c6e8b5100e2e61a4d13addcd1a45bd5 > > > 6. DoS via crafted compressed-RTF size in the TNEF (winmail.dat) file > > > > > > https://github.com/roundcube/roundcubemail/commit/bf253c72d4293c93fda511b8464fe9cb34b522c1 > > > > CVE-2026-62641 was assigned for this issue. > > > > As for the previous uploads, I suggest to follow 1.6.x (upstream's > > current LTS release) for trixie-security. Tested debdiff attached. The > > upstream diff [0] is pretty targeted already, although the 2 Enigma > > changes are not security security related and arguably don't belong to > > Debian stable. If you prefer I can prepare another debdiff with only > > the targeted changes linked above. > > > > The proposed upload also includes a fix to restore with PHP <8 > > (unsupported since bookworm, the change is trivial enough to be worth > > doing), see #1138086. > > Please go ahead with the upload of the tested variant rebasing to the > new upstream version.
The upload arrived, I will try to release the DSA this afternoon or tonight. Regards, Salvatore

