<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">

  <title>Roundcube Webmail Project News</title>
  <link href="https://roundcube.net/feeds/atom.xml" rel="self" />
  <link href="https://roundcube.net" />
  <updated>2026-03-29T10:12:09+00:00</updated>
  <id>https://roundcube.net</id>
  <author>
    <name>Roundcube Webmail Dev Team</name>
  </author>

  
  <entry>
    <title>Security updates 1.7-rc6, 1.6.15 and 1.5.15 released</title>
    <link href="https://roundcube.net/news/2026/03/29/security-updates-1.7-rc6-1.6.15-1.5.15" />
    <updated>2026-03-29T00:00:00+00:00</updated>
    <id>https://roundcube.net/news/2026/03/29/security-updates-1.7-rc6-1.6.15-1.5.15</id>
    <content type="html">&lt;p&gt;We just published security updates to the 1.6 and 1.5 LTS versions of Roundcube Webmail, as well as a release candidate for coming 1.7.
They contain fixes for recently reported set of security vulnerabilities.&lt;/p&gt;

&lt;h2 id=&quot;security-fixes&quot;&gt;Security fixes&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke, reported by class_nzm.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;See the full changelogs in the release notes on the Github download pages for the updated versions&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc6&quot;&gt;1.7-rc6&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.6.15&quot;&gt;1.6.15&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.5.15&quot;&gt;1.5.15&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We strongly recommend to update your productive installations of Roundcube with this new versions.&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>Security updates 1.7-rc5, 1.6.14 and 1.5.14 released</title>
    <link href="https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14" />
    <updated>2026-03-18T00:00:00+00:00</updated>
    <id>https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14</id>
    <content type="html">&lt;p&gt;We just published security updates to the 1.6 and 1.5 LTS versions of Roundcube Webmail, as well as a release candidate for coming 1.7.
They contain fixes for recently reported set of security vulnerabilities.&lt;/p&gt;

&lt;h2 id=&quot;security-fixes&quot;&gt;Security fixes&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;Fix pre-auth arbitrary file write via unsafe deserialization in redis/memcache session handler, reported by y0us.&lt;/li&gt;
  &lt;li&gt;Fix bug where a password could get changed without providing the old password, reported by flydragon777.&lt;/li&gt;
  &lt;li&gt;Fix IMAP Injection + CSRF bypass in mail search, reported by Martila Security Research Team.&lt;/li&gt;
  &lt;li&gt;Fix remote image blocking bypass via various SVG animate attributes, reported by nullcathedral.&lt;/li&gt;
  &lt;li&gt;Fix remote image blocking bypass via a crafted body background attribute, reported by nullcathedral.&lt;/li&gt;
  &lt;li&gt;Fix fixed position mitigation bypass via use of !important, reported by nullcathedral.&lt;/li&gt;
  &lt;li&gt;Fix XSS issue in a HTML attachment preview, reported by aikido_security.&lt;/li&gt;
  &lt;li&gt;Fix SSRF + Information Disclosure via stylesheet links to a local network hosts, reported by Georgios Tsimpidas (aka Frey), Security Researcher at https://i0.rs/.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;See the full changelogs in the release notes on the Github download pages for the updated versions&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc5&quot;&gt;1.7-rc5&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.6.14&quot;&gt;1.6.14&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.5.14&quot;&gt;1.5.14&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We strongly recommend to update your productive installations of Roundcube with this new versions.&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>Roundcube 1.7 RC4 released</title>
    <link href="https://roundcube.net/news/2026/02/13/roundcube-1.7-rc4-released" />
    <updated>2026-02-13T00:00:00+00:00</updated>
    <id>https://roundcube.net/news/2026/02/13/roundcube-1.7-rc4-released</id>
    <content type="html">&lt;p&gt;We just published the fourth release candidate for the next major version 1.7 of Roundcube webmail.&lt;/p&gt;

&lt;p&gt;This release fixes two minor issues, it’s mostly published to fix a file permission problem in the previous release v1.7-rc3.&lt;/p&gt;

&lt;p&gt;The changes are:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Ensure correct file permissions when building a release.&lt;/li&gt;
  &lt;li&gt;Installer: Fix broken link to download the created configuration file (#10092)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The tarballs can be downloaded &lt;a href=&quot;https://roundcube.net/download/&quot;&gt;from roundcube.net/download&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Or directly from &lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc4&quot;&gt;the release page at github.com&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;We believe it is production ready, but we recommend to test it on a separate environment.&lt;/p&gt;

&lt;p&gt;Migrate existing configs with either the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;installto.sh&lt;/code&gt; or the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;update.sh&lt;/code&gt; scripts.&lt;/p&gt;

&lt;p&gt;And don’t forget to backup your data before installing it!&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>Roundcube 1.7 RC3 released</title>
    <link href="https://roundcube.net/news/2026/02/09/roundcube-1.7-rc3-released" />
    <updated>2026-02-09T00:00:00+00:00</updated>
    <id>https://roundcube.net/news/2026/02/09/roundcube-1.7-rc3-released</id>
    <content type="html">&lt;p&gt;We just published the third release candidate for the next major version 1.7 of Roundcube webmail.&lt;/p&gt;

&lt;p&gt;This release fixes two security issues, and contains a few more fixes for several issues.&lt;/p&gt;

&lt;p&gt;The security fixes are:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Fix CSS injection vulnerability reported by CERT Polska.&lt;/li&gt;
  &lt;li&gt;Fix remote image blocking bypass via SVG content reported by nullcathedral.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For the full changelog please see &lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc3&quot;&gt;the release page&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The tarballs can be downloaded &lt;a href=&quot;https://roundcube.net/download/&quot;&gt;via roundcube.net&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Or directly from &lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc3&quot;&gt;the release page at github.com&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;We believe it is production ready, but we recommend to test it on a separate environment.&lt;/p&gt;

&lt;p&gt;Migrate existing configs with either the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;installto.sh&lt;/code&gt; or the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;update.sh&lt;/code&gt; scripts.&lt;/p&gt;

&lt;p&gt;And don’t forget to backup your data before installing it!&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>Security updates 1.6.13 and 1.5.13 released</title>
    <link href="https://roundcube.net/news/2026/02/08/security-updates-1.6.13-and-1.5.13" />
    <updated>2026-02-08T00:00:00+00:00</updated>
    <id>https://roundcube.net/news/2026/02/08/security-updates-1.6.13-and-1.5.13</id>
    <content type="html">&lt;p&gt;We just published security updates to the 1.6 and 1.5 LTS versions of Roundcube Webmail.
They both contain fixes for recently reported two security vulnerabilities.&lt;/p&gt;

&lt;h2 id=&quot;security-fixes&quot;&gt;Security fixes&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;Fix CSS injection vulnerability reported by CERT Polska.&lt;/li&gt;
  &lt;li&gt;Fix remote image blocking bypass via SVG content reported by nullcathedral.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;See the full changelogs in the release notes on the Github download pages for the updated versions
&lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.6.13&quot;&gt;1.6.13&lt;/a&gt; and &lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.5.13&quot;&gt;1.5.13&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;We strongly recommend to update all productive installations of Roundcube 1.6.x and 1.5.x with this new versions.&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>Roundcube 1.7 RC2 released</title>
    <link href="https://roundcube.net/news/2025/12/15/roundcube-1.7-rc2-released" />
    <updated>2025-12-15T00:00:00+00:00</updated>
    <id>https://roundcube.net/news/2025/12/15/roundcube-1.7-rc2-released</id>
    <content type="html">&lt;p&gt;We just published the second release candidate for the next major version 1.7 of Roundcube webmail.&lt;/p&gt;

&lt;p&gt;This release fixes two security issues and one syntax error in a database migration file for Postgres databases.&lt;/p&gt;

&lt;p&gt;The changes are:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Fix Cross-Site-Scripting vulnerability via SVG’s animate tag reported by Valentin T., CrowdStrike.&lt;/li&gt;
  &lt;li&gt;Fix Information Disclosure vulnerability in the HTML style sanitizer reported by somerandomdev.&lt;/li&gt;
  &lt;li&gt;Fix syntax error in DDL scripts for Postgres (#10052)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We believe it is production ready, but we recommend to test it on a separate environment.&lt;/p&gt;

&lt;p&gt;Migrate existing configs with either the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;installto.sh&lt;/code&gt; or the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;update.sh&lt;/code&gt; scripts.&lt;/p&gt;

&lt;p&gt;And don’t forget to backup your data before installing it!&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>Security updates 1.6.12 and 1.5.12 released</title>
    <link href="https://roundcube.net/news/2025/12/13/security-updates-1.6.12-and-1.5.12" />
    <updated>2025-12-13T00:00:00+00:00</updated>
    <id>https://roundcube.net/news/2025/12/13/security-updates-1.6.12-and-1.5.12</id>
    <content type="html">&lt;p&gt;We just published security updates to the 1.6 and 1.5 LTS versions of Roundcube Webmail.
They both contain fixes for recently reported two security vulnerabilities.&lt;/p&gt;

&lt;h2 id=&quot;security-fixes&quot;&gt;Security fixes&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;Fix Cross-Site-Scripting vulnerability via SVG’s animate tag reported by Valentin T., CrowdStrike.&lt;/li&gt;
  &lt;li&gt;Fix Information Disclosure vulnerability in the HTML style sanitizer reported by somerandomdev.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;See the full changelogs in the release notes on the Github download pages for the updated versions
&lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.6.12&quot;&gt;1.6.12&lt;/a&gt; and &lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.5.12&quot;&gt;1.5.12&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;We strongly recommend to update all productive installations of Roundcube 1.6.x and 1.5.x with this new versions.&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>Roundcube 1.7 RC released</title>
    <link href="https://roundcube.net/news/2025/12/10/roundcube-1.7-rc-released" />
    <updated>2025-12-10T00:00:00+00:00</updated>
    <id>https://roundcube.net/news/2025/12/10/roundcube-1.7-rc-released</id>
    <content type="html">&lt;p&gt;The development team is pleased to announce the release candidate for the next major version 1.7 of Roundcube webmail!&lt;/p&gt;

&lt;p&gt;With this milestone we introduce a few breaking changes (see below) and some further improvements in comparison to 1.7-beta2.&lt;/p&gt;

&lt;p&gt;Some noteworthy changes are:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Add scope parameter to contact search (#9863)&lt;/li&gt;
  &lt;li&gt;Add ability to chose from all available contact fields on CSV import (#9419)&lt;/li&gt;
  &lt;li&gt;Add a new plugin called &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;markdown_editor&lt;/code&gt; that provides an alternative editor to compose emails using Markdown syntax.&lt;/li&gt;
  &lt;li&gt;Add rel=’noopener’ to all links opening in a new window to mitigate against misuse in older browsers.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4 id=&quot;breaking-changes&quot;&gt;Breaking Changes&lt;/h4&gt;

&lt;ul&gt;
  &lt;li&gt;Remove &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;contact_search_name&lt;/code&gt; option in favor of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;contactlist_name_template&lt;/code&gt; (#9832)&lt;/li&gt;
  &lt;li&gt;Replace session attribute &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;changed&lt;/code&gt; by &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;expires_at&lt;/code&gt; (to allow for variable session lengths per-user in a future change).&lt;/li&gt;
  &lt;li&gt;Password: Removed the (insecure) virtualmin driver (#8007)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For full details and download links please read the &lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc&quot;&gt;release notes&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;We believe it is production ready, but we recommend to test it on a separate environment.&lt;/p&gt;

&lt;p&gt;Migrate existing configs with either the installto.sh or the update.sh scripts.&lt;/p&gt;

&lt;p&gt;And don’t forget to backup your data before installing it!&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>Roundcube 1.7 beta2 released</title>
    <link href="https://roundcube.net/news/2025/10/01/roundcube-1.7-beta2-released" />
    <updated>2025-10-01T00:00:00+00:00</updated>
    <id>https://roundcube.net/news/2025/10/01/roundcube-1.7-beta2-released</id>
    <content type="html">&lt;p&gt;The development team is pleased to announce the second beta release for the next major version 1.7 of Roundcube webmail.&lt;/p&gt;

&lt;p&gt;With this milestone we introduce some more fixes, and bring full support for the early version of PHP 8.5.&lt;/p&gt;

&lt;p&gt;It does not include breaking changes (beyond those of 1.7-beta).&lt;/p&gt;

&lt;p&gt;Some noteworthy changes are:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Support PHP v8.5(-pre) without deprecation warnings.&lt;/li&gt;
  &lt;li&gt;Support IPv6 in database DSN (#9937)&lt;/li&gt;
  &lt;li&gt;Use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;htmleditor&lt;/code&gt; setting also for identity signature (#9954)&lt;/li&gt;
  &lt;li&gt;Fix regression in handling of non-unicode characters in a plain text message (#9953)&lt;/li&gt;
  &lt;li&gt;Fix parsing of inline styles that aren’t well-formatted (#9948)&lt;/li&gt;
  &lt;li&gt;Support early MIME types for S/MIME encrypted messages (#9973)&lt;/li&gt;
  &lt;li&gt;Only apply fix_path for href attrib in &lt;link /&gt;s (#9943)&lt;/li&gt;
  &lt;li&gt;Show homograph-warning-icon before email address, unify warning wording (#9945)&lt;/li&gt;
  &lt;li&gt;Show full details with warning icon in case of phishing suspicion (#9945)&lt;/li&gt;
  &lt;li&gt;Prepend group-names to display-name (#9945) Thanks to coco_melon for the reporting!&lt;/li&gt;
  &lt;li&gt;Wash the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;name&lt;/code&gt; attribute also on more elements (#9949) – Thanks to pwn.ai by Octagon Networks for the reporting!&lt;/li&gt;
  &lt;li&gt;Sanitize filename on download (#9960)&lt;/li&gt;
  &lt;li&gt;Drop Internet Explorer from supported browsers (#9963)&lt;/li&gt;
  &lt;li&gt;Enforce leading backslash for non-namespaced non-Roundcube uses (#9935)&lt;/li&gt;
  &lt;li&gt;Use asset_url() instead of get_skin_file() for deleteicon on contact edit form (#9933)&lt;/li&gt;
  &lt;li&gt;Several changes to the test tooling.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For full details please see the &lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.7-beta2&quot;&gt;release notes&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;This is a beta release and we recommend to test it on a separate environment.
Migrate existing configs with either the installto.sh or the update.sh scripts.&lt;/p&gt;

&lt;p&gt;And don’t forget to backup your data before installing it!&lt;/p&gt;
</content>
  </entry>
  
  <entry>
    <title>Roundcube 1.7 beta released</title>
    <link href="https://roundcube.net/news/2025/07/14/roundcube-1.7-beta-released" />
    <updated>2025-07-14T00:00:00+00:00</updated>
    <id>https://roundcube.net/news/2025/07/14/roundcube-1.7-beta-released</id>
    <content type="html">&lt;p&gt;The development team is pleased to announce the beta release for the next major version 1.7 of Roundcube webmail.&lt;/p&gt;

&lt;p&gt;With this milestone we introduce a few breaking changes, some new features, and bring full support for PHP 8.4.&lt;/p&gt;

&lt;p&gt;Some noteworthy changes are:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Make &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;public_html/&lt;/code&gt; mandatory as entry-point for HTTP daemons, protecting all installations better.&lt;/li&gt;
  &lt;li&gt;Improve support for OAuth2 (e.g. supporting OpenID Connect discovery URLs).&lt;/li&gt;
  &lt;li&gt;A Mouse-over menu on the messages list with quick action icons.&lt;/li&gt;
  &lt;li&gt;Advanced mail search syntax with more possibilities – you can now use e.g. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;is:unread&lt;/code&gt; to only match unread messages. The &lt;a href=&quot;https://github.com/roundcube/roundcubemail/blob/master/tests/Actions/Mail/SearchTest.php#L139&quot;&gt;test file&lt;/a&gt; has a list of implemented keywords.&lt;/li&gt;
  &lt;li&gt;Message parts of content-type &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;text/markdown&lt;/code&gt; are now rendered to HTML (if they are designated for showing).&lt;/li&gt;
  &lt;li&gt;Add a ‘php’ logging driver, which passes all log statements to PHP’s &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;error_log&lt;/code&gt; handler, allowing to unify all log output.&lt;/li&gt;
  &lt;li&gt;Requires PHP v8.1 or newer.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;breaking-changes&quot;&gt;Breaking Changes&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;Dropped support for PHP &amp;lt; 8.1.&lt;/li&gt;
  &lt;li&gt;Removed support for MS SQL Server and Oracle.&lt;/li&gt;
  &lt;li&gt;Make public_html/ entry-point mandatory, all static resources are served via static.php.&lt;/li&gt;
  &lt;li&gt;Removed &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;apc&lt;/code&gt; cache driver (replaced by &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;apcu&lt;/code&gt; cache driver).&lt;/li&gt;
  &lt;li&gt;Change &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;smtp_log&lt;/code&gt; option default value to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;false&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For full details please see the &lt;a href=&quot;https://github.com/roundcube/roundcubemail/releases/tag/1.7-beta&quot;&gt;release notes&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;This is a beta release and we recommend to test it on a separate environment.
Migrate existing configs with either the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;installto.sh&lt;/code&gt; or the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;update.sh&lt;/code&gt; scripts.&lt;/p&gt;

&lt;p&gt;And don’t forget to backup your data before installing it!&lt;/p&gt;
</content>
  </entry>
  

</feed>
