In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unvalidated CSS Proxy Response Causing XSS and Information Disclosure in Roundcube Webmail |
Mon, 17 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing. | |
| First Time appeared |
Roundcube
Roundcube webmail |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roundcube
Roundcube webmail |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-17T12:40:29.903Z
Reserved: 2026-08-17T12:40:29.556Z
Link: CVE-2026-74998
No data.
Status : Received
Published: 2026-08-17T13:16:54.270
Modified: 2026-08-17T13:16:54.270
Link: CVE-2026-74998
No data.
OpenCVE Enrichment
Updated: 2026-08-17T15:00:08Z
Weaknesses