Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-06325

Опубликовано: 18 мар. 2026
Источник: fstec
CVSS3: 8.2
CVSS2: 8.5
EPSS Низкий

Описание

Уязвимость функции удаленной блокировки изображений почтового клиента RoundCube Webmail связана с отсутствием проверки корректности принимаемых запросов. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, раскрыть защищаемую информацию и обойти существующие ограничения безопасности

Вендор

ООО «Ред Софт»
The RoundCube Team

Наименование ПО

РЕД ОС
RoundCube Webmail

Версия ПО

8.0 (РЕД ОС)
до 1.5.15 (RoundCube Webmail)
до 1.6.15 (RoundCube Webmail)
до 1.7-rc6 (RoundCube Webmail)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 8,5)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 8,2)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://github.com/roundcube/roundcubemail/commit/7ad62de184368bf42c0f522d1aacc030f5ddcc46
https://github.com/roundcube/roundcubemail/commit/9d18d524f3cc211003fc99e2e54eed09a2f3da88
https://github.com/roundcube/roundcubemail/commit/fe1320b199d3a2f58351bb699c9ed4316e73221b
https://github.com/roundcube/roundcubemail/releases/tag/1.5.15
https://github.com/roundcube/roundcubemail/releases/tag/1.6.15
https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc6
https://roundcube.net/news/2026/03/29/security-updates-1.7-rc6-1.6.15-1.5.15
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-35545

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 25%
0.00329
Низкий

8.2 High

CVSS3

8.5 High

CVSS2

Связанные уязвимости

CVSS3: 8.2
redos
3 месяца назад

Уязвимость roundcubemail

CVSS3: 5.3
ubuntu
4 месяца назад

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.

CVSS3: 5.3
nvd
4 месяца назад

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.

CVSS3: 5.3
debian
4 месяца назад

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. ...

CVSS3: 5.3
github
4 месяца назад

Roundcube Webmail: Remote image blocking feature can be bypassed via SVG content in an e-mail message

EPSS

Процентиль: 25%
0.00329
Низкий

8.2 High

CVSS3

8.5 High

CVSS2