CVE-2026-62643
개요
A flaw was found in Roundcube Webmail. Insufficient sanitization of Cascading Style Sheets (CSS) within HTML email messages allows a remote attacker to perform Server-Side Request Forgery (SSRF) or disclose sensitive information. This vulnerability occurs when stylesheet links point to local network hosts, potentially enabling access to internal resources or sensitive data. This issue is a result of incomplete fixes for previously identified vulnerabilities.
내용
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
취약점 이해 (CWE)
Confidentiality
Technical Impact: Read Application Data
Integrity
Technical Impact: Execute Unauthorized Code or Commands
Access Control
Technical Impact: Bypass Protection Mechanism
By providing URLs to unexpected hosts or ports, attackers can make it appear that the server is sending the request, possibly bypassing access controls such as firewalls that prevent the attackers from accessing the URLs directly. The server can be used as a proxy to conduct port scanning of hosts in internal networks, use other URLs such as that can access documents on the system (using file://), or use other protocols such as gopher:// or tftp://, which may provide greater control over the contents of requests.