CVE-2026-35391Bulwarkmail · Webmail
Vulnerability data via NVD (ingested)
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in lib/admin/session.ts trusted the first (leftmost) entry of the X-Forwarded-For header, which is fully controlled by the client. An attacker could forge their source IP address to bypass IP-based rate limiting (enabling brute-force attacks against the admin login) or forge audit log entries (making malicious activity appear to originate from arbitrary IP addresses). This vulnerability is fixed in 1.4.11.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-35391product:"Bulwarkmail Webmail"http.html:"Webmail"More intel sources (5)
vuln:CVE-2026-35391vulnerabilities.cve_id: CVE-2026-35391CVE-2026-35391CVE-2026-35391"CVE-2026-35391" exploit -site:nvd.nist.gov