CVE-2026-35391 is a high-severity vulnerability in Bulwark Webmail, a self-hosted webmail client for Stalwart Mail Server. The getClientIP() function in lib/admin/session.ts was trusting the first entry of the X-Forwarded-For header, allowing an attacker to forge their source IP address. This could bypass IP-based rate limiting, enabling brute-force attacks against the admin login, or forge audit log entr [truncated]
CVE-2026-35390 is a security vulnerability in Bulwark Webmail, a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.11, the application incorrectly set the Content-Security-Policy-Report-Only header instead of the enforcing Content-Security-Policy header. This error allowed cross-site scripting (XSS) attacks to occur, as malicious scripts were logged but not blocked. An attacker who [truncated]
A high-severity vulnerability was discovered in Bulwark Webmail, a self-hosted webmail client for Stalwart Mail Server. The issue, tracked as CVE-2026-35389, allows attackers to bypass S/MIME signature verification, potentially leading to email spoofing and phishing attacks. This vulnerability exists due to the lack of validation of the certificate trust chain (checkChain: false) in the S/MIME signature v [truncated]