Webmail
Bulwarkmail · 5 CVEs
CVE-2026-35391
HIGH
Bulwark Webmail getClientIP() trusted client-controlled X-Forwarded-For value, enabling rate limit bypass and audit log…
Apr 6, 2026
CVE-2026-35390
MEDIUM
Content-Security-Policy was set to Report-Only mode, failing to block XSS attacks
Apr 6, 2026
CVE-2026-35389
HIGH
Bulwark Webmail S/MIME signature verification accepted self-signed certificates
Apr 6, 2026
CVE-2026-34834
HIGH
Bulwark Webmail: Authentication Bypass in verifyIdentity() due to missing cookie validation
Apr 2, 2026
CVE-2026-34833
HIGH
Bulwark Webmail: Information Exposure: password returned in /api/auth/session
Apr 2, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-35391 | Bulwark Webmail getClientIP() trusted client-controlled X-Forwarded-For value, enabling rate limit bypass and audit log forgery | HIGH | 0.19% | Apr 6, 2026 |
| CVE-2026-35390 | Content-Security-Policy was set to Report-Only mode, failing to block XSS attacks | MEDIUM | 0.23% | Apr 6, 2026 |
| CVE-2026-35389 | Bulwark Webmail S/MIME signature verification accepted self-signed certificates | HIGH | 0.24% | Apr 6, 2026 |
| CVE-2026-34834 | Bulwark Webmail: Authentication Bypass in verifyIdentity() due to missing cookie validation | HIGH | 0.42% | Apr 2, 2026 |
| CVE-2026-34833 | Bulwark Webmail: Information Exposure: password returned in /api/auth/session | HIGH | 0.27% | Apr 2, 2026 |
Showing 1 to 5 of 5 CVEs