Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6196-1 | roundcube security update |
Github GHSA |
GHSA-5hf6-crg4-fg59 | Roundcube: Bypass of remote image blocking via crafted BODY background attribute |
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Roundcube Webmail Remote Image Blocking Feature Bypass Allows Information Disclosure |
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* |
Fri, 03 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Roundcube Webmail Remote Image Blocking Feature Bypass Allows Information Disclosure | |
| First Time appeared |
Roundcube
Roundcube webmail |
|
| Vendors & Products |
Roundcube
Roundcube webmail |
Fri, 03 Apr 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. | |
| Weaknesses | CWE-669 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-03T12:51:27.986Z
Reserved: 2026-04-03T03:54:17.981Z
Link: CVE-2026-35542
Updated: 2026-04-03T12:51:23.658Z
Status : Analyzed
Published: 2026-04-03T05:16:22.460
Modified: 2026-04-07T20:41:01.040
Link: CVE-2026-35542
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:54:21Z
Debian DSA
Github GHSA