CVE-2026-62642
4.3
MEDIUM
CVSS 3.1
EPSS 0.26%
Description
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
How to fix CVE-2026-62642
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/roundcube—no fix listed
Is CVE-2026-62642 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |