Canarymail is an email security and privacy application whose vulnerability footprint centers on its core mail client product and recurs through weaknesses in certificate validation and protection-mechanism implementation. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Canarymail over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65318CRITICAL When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass t | Dec 16, 2025 | 9.1 | 30 | NO | NO |
CVE-2021-26911HIGH core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode. | Feb 17, 2021 | 7.4 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Canarymail.
Media articles that mention a CVE ID that affects a product developed by Canarymail — matched by CVE ID, not by vendor name.