CVE-2026-62642

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-14 16:17

Updated : 2026-07-20 12:55


NVD link : CVE-2026-62642

Mitre link : CVE-2026-62642

CVE.ORG link : CVE-2026-62642


JSON object : View

Products Affected

roundcube

  • webmail
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')