CVE-2026-9818

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

28 May 2026, 17:16

Type Values Removed Values Added
CWE CWE-184
CVSS v2 : unknown
v3 : 4.7
v2 : unknown
v3 : unknown
References
  • {'url': 'https://advisories.orangecyberdefense.com/advisories/163', 'source': '6064c9f1-42e5-4cc5-a67a-1636d7a9d3fd'}
  • {'url': 'https://github.com/roundcube/roundcubemail/commit/7b52353653a67e6073b97d70eb94047132b78556', 'source': '6064c9f1-42e5-4cc5-a67a-1636d7a9d3fd'}
  • {'url': 'https://github.com/roundcube/roundcubemail/commit/faf867432f51ebbe100382a70a9e3c042415ee1b', 'source': '6064c9f1-42e5-4cc5-a67a-1636d7a9d3fd'}
  • {'url': 'https://github.com/roundcube/roundcubemail/releases/tag/1.6.16', 'source': '6064c9f1-42e5-4cc5-a67a-1636d7a9d3fd'}
  • {'url': 'https://github.com/roundcube/roundcubemail/releases/tag/1.7.1', 'source': '6064c9f1-42e5-4cc5-a67a-1636d7a9d3fd'}
Summary (en) Roundcube's HTML sanitization path for message rendering allows loopback, localhost, RFC1918, link-local, and ULA URLs even when remote content loading is disabled. A remote attacker can send an HTML email that causes the victim's browser to issue requests to local or private-network services simply by opening the message preview. (en) Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

28 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 13:16

Updated : 2026-05-28 17:16


NVD link : CVE-2026-9818

Mitre link : CVE-2026-9818

CVE.ORG link : CVE-2026-9818


JSON object : View

Products Affected

No product.

CWE

No CWE.