dbconfig-common-support.patch
debianize-config.patch
fix-install-path.patch
update-script.patch
use-enchant.patch
default-charset-utf8.patch
debianize-password-plugin.patch
map-sqlite3-to-sqlite.patch
use-embedded-jquery-for-http-authentication.patch
update-composer.patch
update-jsdeps.patch
use-system-JQueryUI.patch
rename-python-to-python3.patch
adjust-test-environment-for-dep8.patch
fix-autoload-locations.patch
mark-flaky-tests-as-such.patch
dont-force-set-session.gc_probability=1.patch
fix-upstream-test-suite.patch
CVE-2024-37384.patch
CVE-2024-37383.patch
Fix-fatal-error-when-parsing-some-TNEF-attachments.patch
Fix-bug-where-an-unhandled-exception-was-caused-by-an-inv.patch
Fix-infinite-loop-when-parsing-malformed-Sieve-script.patch
Fix-bug-where-imap_conn_option-s-socket-was-ignored.patch
CVE-2024-42009.patch
CVE-2024-42008.patch
Fix-regression-where-printing-scaling-rotating-image-atta.patch
CVE-2024-42010.patch
Fix-regression-where-HTML-messages-were-displayed-unstyle.patch
CVE-2025-49113.patch
CVE-2025-68461.patch
CVE-2025-68460/01-08de250fb.patch
CVE-2025-68460/02-a7349a4e2.patch
CVE-2026-25916/01-036e851b6.patch
CVE-2026-25916/02-2b5625f1d.patch
CVE-2026-26079/01-1f4c3a5af.patch
CVE-2026-26079/02-2b5625f1d.patch
CVE-2026-26079/03-53d75d5df.patch
CVE-2026-35537.patch
CVE-2026-35541.patch
CVE-2026-35538/01-b18a8fa8e.patch
CVE-2026-35538/02-6b137adda.patch
CVE-2026-35543.patch
CVE-2026-35542/01-fde14d01a.patch
CVE-2026-35542/02-5aba847cb.patch
CVE-2026-35544.patch
CVE-2026-35539.patch
CVE-2026-35540.patch
CVE-2026-35545.patch
CVE-2026-48849.patch
CVE-2026-48848.patch
CVE-2026-48842.patch
CVE-2026-48843.patch
CVE-2026-48846.patch
CVE-2026-48845.patch
CVE-2026-48847.patch
CVE-2026-48844.patch
CVE-2026-62642/01-a00732134.patch
CVE-2026-62642/02-132ac8dd5.patch
CVE-2026-62644/01-83150ce04.patch
CVE-2026-62644/02-5cdc6a48b.patch
CVE-2026-62644/03-ce418a22b.patch
CVE-2026-54432.patch
CVE-2026-62643.patch
CVE-2026-54433.patch
CVE-2026-62641.patch
Fix-out-of-bounds-string-reads-on-truncated-compressed-RT.patch
CVE-2026-74998.patch
CVE-2026-75006/01-8a92380b0.patch
CVE-2026-75006/02-92f85c883.patch
CVE-2026-75003.patch
CVE-2026-75007.patch
CVE-2026-75004.patch
CVE-2026-74997/01-b8f90e28a.patch
CVE-2026-74997/02-495d21163.patch
CVE-2026-75002.patch
CVE-2026-75010.patch
CVE-2026-74999.patch
CVE-2026-75000.patch
Tests-MessageMock.patch
Fix-CSS-declaration-smuggling-via-un-encoded-ampersand-em.patch
Fix-CSS-property-injection-via-body-background-attribute.patch
Backport-cleanup.patch
Backport-fix.patch
Fix.patch
Fix-email-header-injection-via-bare-CR-in-subject-Field.patch
Fix-email-header-injection-via-C-escape-r-in-the-recipien.patch
Fix-email-header-injection-via-identity-s-organization-fi.patch
Fix-zero-click-stored-XSS-via-TNEF-MIME-tag-injection-in-.patch
Fix-XSS-in-the-HTML-editor-using-text-enriched-part-conte.patch
CS-fixes.patch
Backport-fix-1.patch
Fix-cross-user-access-in-contact-group-membership-add-rem.patch
Fix-is_local_url-bypass-via-trailing-dot-FQDN-in-styleshe.patch
Fix-remote-content-blocking-bypass-via-CSS-escapes-in-Fun.patch
Fix-remote-content-blocker-bypass-via-SVG-SMIL-src-animat.patch
Fix-SSRF-bypass-in-Roundcube-CSS-proxy-via-hexadecimal-IP.patch
Avoid-dependency-on-new-package-mlocati-ip-lib.patch
