Medium severity4.3NVD Advisory· Published Jul 14, 2026· Updated Jul 20, 2026
CVE-2026-62642
CVE-2026-62642
Description
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
Affected products
2- Range: <1.6.17, <1.7.2
Patches
Vulnerability mechanics
References
7- github.com/roundcube/roundcubemail/commit/132ac8dd5a55c8466be12de1daf84355697ffa89nvdPatch
- github.com/roundcube/roundcubemail/commit/877269c79359d959a94f13c9070cab0f3389c193nvdPatch
- github.com/roundcube/roundcubemail/commit/a007321346380136b3de2bd75b486b04f63c0d38nvdPatch
- github.com/roundcube/roundcubemail/commit/fb952956c6eaf29e963f1a718d028d66e7957ce0nvdPatch
- roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2nvdVendor Advisory
- github.com/roundcube/roundcubemail/releases/tag/1.6.17nvdRelease Notes
- github.com/roundcube/roundcubemail/releases/tag/1.7.2nvdRelease Notes
News mentions
1- Roundcube Webmail: Four Vulnerabilities Disclosed, Ranging from DoS to Account TakeoverVypr Intelligence · Jul 15, 2026