ZeroHour

CVE-2026-62642

CVSS 3.1
6.5 medium
EPSS
<1%p42
Published
()
Modified
Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.

Vendors
roundcube
Products
webmail
Weakness
CWE-835
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.