Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade roundcube | Jul 30, 2024 | Aug 20, 2019 |
| Gentoo Linux | — | Upgrade mail-client/roundcube. | Jul 23, 2025 | Aug 20, 2019 |
| Ubuntu | — | Upgrade roundcube-plugins (Ubuntu Pro)Upgrade roundcube-core (Ubuntu Pro) | Nov 19, 2024 | Aug 20, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub