EXPOSURES › CVE-2026-62643
CVE-2026-62643
HIGH
DETAIL
SourceNVD · cve
Published2026-07-14
CVSS7.2
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-62643 ↗
▸ RECOMMENDED ACTION Patch the affected products and confirm your instances are covered.
PLAYERS IMPLICATED
DESCRIPTION
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.