{"advisories":[{"id":"DLA-2840-1","source":"dla","title":"roundcube security update","url":"https://lists.debian.org/debian-lts-announce/2021/12/msg00004.html"},{"id":"DSA-5013-1","source":"dsa","title":"roundcube security update","url":"https://lists.debian.org/debian-security-announce/2021/msg00199.html"},{"id":"USN-5182-1","source":"usn","title":"Roundcube Webmail vulnerabilities","url":"https://ubuntu.com/security/notices/USN-5182-1"}],"cve":"CVE-2021-44026","epss":{"score":0.69882},"kev":{"dateAdded":"2023-06-22T00:00:00+00:00","dueDate":"2023-07-13T00:00:00+00:00"},"mitre":{"cpes":[],"created":"2021-11-19T03:47:27+00:00","description":"Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2021/44xxx/CVE-2021-44026.json","references":["https://bugs.debian.org/1000156","https://github.com/roundcube/roundcubemail/commit/c8947ecb762d9e89c2091bda28d49002817263f1","https://github.com/roundcube/roundcubemail/commit/ee809bde2dcaa04857a919397808a7296681dcfa","https://lists.debian.org/debian-lts-announce/2021/12/msg00004.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NDVGIZMQJ5IOM47Y3SAAJRN5VPANKTKO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TP3Y5RXTUUOUODNG7HFEKWYNIPIT2NL4/","https://www.debian.org/security/2021/dsa-5013"],"title":null,"updated":"2025-10-21T23:25:24.717000+00:00","vendors":[],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"],"created":"2021-11-19T04:15:07.197000+00:00","description":"Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.","metrics":{"cvssV2_0":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2021/CVE-2021-44026.json","references":["https://bugs.debian.org/1000156","https://github.com/roundcube/roundcubemail/commit/c8947ecb762d9e89c2091bda28d49002817263f1","https://github.com/roundcube/roundcubemail/commit/ee809bde2dcaa04857a919397808a7296681dcfa","https://lists.debian.org/debian-lts-announce/2021/12/msg00004.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NDVGIZMQJ5IOM47Y3SAAJRN5VPANKTKO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TP3Y5RXTUUOUODNG7HFEKWYNIPIT2NL4/","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44026","https://www.debian.org/security/2021/dsa-5013"],"title":null,"updated":"2026-06-17T04:11:48.777000+00:00","vendors":["debian","debian$PRODUCT$debian_linux","fedoraproject","fedoraproject$PRODUCT$fedora","roundcube","roundcube$PRODUCT$webmail"],"weaknesses":["CWE-89"]},"opencve":{"changes":[{"created":"2025-02-04T20:15:00+00:00","data":[{"details":{"added":{"kev":{"dateAdded":"2023-06-22"},"ssvc":{"options":{"Automatable":"yes","Exploitation":"active","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"1e57c265-ae7d-4d9e-9335-420d72e689e1"},{"created":"2025-07-16T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.68761},"old":{"score":0.68079}}}},"type":"metrics"}],"id":"f0e72413-8427-4c12-851f-61705acfaf61"},{"created":"2025-10-21T19:30:00+00:00","data":[{"details":{"added":["https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44026"],"removed":[]},"type":"references"}],"id":"6823e5a2-0a50-4218-b4ef-de65add56051"},{"created":"2025-10-21T20:30:00+00:00","data":[{"details":{"added":[],"removed":["https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44026"]},"type":"references"}],"id":"c9544899-fa51-4174-a755-eac55b55d736"},{"created":"2025-10-22T00:15:00+00:00","data":[{"details":{"added":["https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44026"],"removed":[]},"type":"references"}],"id":"15932b5b-4ba2-4c9b-bb0a-823ef819792b"}],"cpes":{"data":["cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2021-11-19T03:47:27+00:00","provider":"mitre"},"description":{"data":"Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"provider":"nvd"},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"vulnrichment"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.69882},"provider":"first"},"kev":{"data":{"dateAdded":"2023-06-22T00:00:00+00:00","dueDate":"2023-07-13T00:00:00+00:00"},"provider":"cisa"},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"active","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://bugs.debian.org/1000156","https://github.com/roundcube/roundcubemail/commit/c8947ecb762d9e89c2091bda28d49002817263f1","https://github.com/roundcube/roundcubemail/commit/ee809bde2dcaa04857a919397808a7296681dcfa","https://lists.debian.org/debian-lts-announce/2021/12/msg00004.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NDVGIZMQJ5IOM47Y3SAAJRN5VPANKTKO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TP3Y5RXTUUOUODNG7HFEKWYNIPIT2NL4/","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44026","https://www.debian.org/security/2021/dsa-5013"],"providers":["mitre","nvd","vulnrichment"]},"title":{"data":null,"provider":null},"updated":{"data":"2025-11-04T15:00:10.590000+00:00","provider":"nvd"},"vendors":{"data":["debian","debian$PRODUCT$debian_linux","fedoraproject","fedoraproject$PRODUCT$fedora","roundcube","roundcube$PRODUCT$webmail"],"providers":["nvd"]},"weaknesses":{"data":["CWE-89"],"providers":["nvd","vulnrichment"]}},"vulnrichment":{"cpes":[],"created":"2021-11-19T03:47:27+00:00","description":"Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{},"kev":{"dateAdded":"2023-06-22"},"ssvc":{"options":{"Automatable":"yes","Exploitation":"active","Technical Impact":"total"},"version":"2.0.3"}},"references":["https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44026"],"title":null,"updated":"2025-02-04T19:32:52.948000+00:00","vendors":[],"vulnrichment_repo_path":"2021/44xxx/CVE-2021-44026.json","weaknesses":["CWE-89"]}}