Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/bulwarkmail/webmail

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-35391 is a high-severity vulnerability in Bulwark Webmail versions prior to 1.4.11. The vulnerability arises because the getClientIP() function trusts the first entry of the X-Forwarded-For header, which can be manipulated by an attacker. This allows attackers to forge their source IP address, potentially bypassing IP-based rate limiting and enabling brute-force attacks against the admin login. Additionally, attackers can forge audit log entries to mask malicious activity. The issue is fixed in version 1.4.11.

Join the discussion

Bulwark Webmail versions prior to 1.4.11 have a cross-site scripting (XSS) vulnerability due to the reverse proxy setting a Content-Security-Policy-Report-Only header instead of an enforcing Content-Security-Policy header. This allowed script injection via crafted email HTML, enabling arbitrary JavaScript execution in the application's context. The vulnerability is fixed in version 1.4.11.

Join the discussion

Bulwark Webmail versions prior to 1.4.11 contain a vulnerability in S/MIME signature verification where the certificate trust chain was not validated. This means emails signed with self-signed or untrusted certificates were incorrectly shown as having valid signatures. The issue is addressed in version 1.4.11. The vulnerability has a high severity with a CVSS score of 8.7.

Join the discussion

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() function contained logic that returned true if no session cookies were present. This allowed unauthenticated attackers to bypass security checks and access/modify user settings via the /api/settings endpoint by providing arbitrary headers. This issue has been patched in version 1.4.10.

Join the discussion

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext password in the JSON response. This exposed credentials to browser logs, local caches, and network proxie. This issue has been patched in version 1.4.10.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/bulwarkmail/webmail
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses