---
cve: "CVE-2026-62642"
severity: "MEDIUM"
cvss: 4.3
epss: "28%"
vendor: "Roundcube"
kev: false
exploited: false
published: "2026-07-14 16:17:04"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T10:15:12+02:00"
---

# CVE-2026-62642

> 4.3 MEDIUM · 🧪 PoC

## Beschreibung

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Gering | warn |

## Patch verfügbar (OSV)

- e3c8a05a04d60e969475631951c8e555c83374b7 (Commit)
- a08bc8f59bbd28cd3d863479478127e35beb959d (Commit)

## Referenzen

- <https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2>
- <https://github.com/roundcube/roundcubemail/releases/tag/1.7.2>
- <https://github.com/roundcube/roundcubemail/commit/877269c79359d959a94f13c9070cab0f3389c193>
- <https://github.com/roundcube/roundcubemail/commit/fb952956c6eaf29e963f1a718d028d66e7957ce0>
- <https://github.com/roundcube/roundcubemail/releases/tag/1.6.17>
- <https://github.com/roundcube/roundcubemail/commit/a007321346380136b3de2bd75b486b04f63c0d38>
- <https://github.com/roundcube/roundcubemail/commit/132ac8dd5a55c8466be12de1daf84355697ffa89>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-62642) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
