Bulwarkmail develops a webmail application where the durable vulnerability signal centers on authentication and data-protection deficiencies: cleartext storage of sensitive information, improper authentication mechanisms, certificate validation gaps, cross-site scripting, and reliance on less-trusted data sources. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bulwarkmail over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35391HIGH Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in lib/admin/session.ts trusted the first (leftmost) entry of | Apr 6, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-35389HIGH Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certificate trust chain (checkChain: f | Apr 6, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-34834HIGH Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() function contained logic that returned true if no session co | Apr 2, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-34833HIGH Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext passw | Apr 2, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-35390MEDIUM Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts) set the Content-Security-Policy-Report-Only header instead o | Apr 6, 2026 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bulwarkmail.
Media articles that mention a CVE ID that affects a product developed by Bulwarkmail — matched by CVE ID, not by vendor name.