This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+6 more
Affected surfaces
Summary
AI summaryRoundcube upgraded to 1.6.17 fixing CVE-2026-54432 and CVE-2026-54433.
Full changelog
Changelog :mailbox:
-
roundcube 1.6.17 - fix multiple CVEs: CVE-2026-54432 CVE-2026-54433
-
This release was triggered by PR/Issue 4073.
-
The release notes of the original main release can be accessed via menu item 'Release notes' on mailu.io.
Update
The main version X.Y (e.g. 1.9) will always reflect the latest version of the branch. To update your Mailu installation simply pull the latest images `docker compose pull && docker compose up -d`.
The pinned version X.Y.Z (e.g. 1.9.1) is not updated. It is pinned to the commit that was used for creating this release. You can use a pinned version to make sure your Mailu installation is not suddenly updated when recreating containers. The pinned version allows the user to manually update. It also allows to go back to a previous pinned version.
Security Fixes
- CVE-2026-54432 — fixed in Roundcube 1.6.17
- CVE-2026-54433 — fixed in Roundcube 1.6.17
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]