← Back to CVE search

CVE-2026-62642

Roundcube Webmail

Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.

CVSS 4.3EPSS 0.27699999999999997%Risk 0.44
View source
Published
2026-07-14 16:17:04
Affected versions
<1.6.17, <1.7.2
Type
Web application
Last modified
2026-07-20 12:55:28
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L