Nixpkgs Security Tracker

Login with GitHub

Details of issue NIXPKGS-2026-0244

NIXPKGS-2026-0244
published on 15 Feb 2026
Permalink CVE-2026-25916
4.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
updated 1 month, 1 week ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package ayatana-webmail
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block …

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

Affected products

Webmail
  • <1.5.13
  • <1.6.13
Issue write-up: https://nullcathedral.com/posts/2026-02-08-roundcube-svg-feimage-remote-image-bypass/
Upstream patch: https://github.com/roundcube/roundcubemail/commit/26d7677471b68ff2d02ebe697cb606790b0cf52f