PT-2026-30729 · Unknown · Stalwart Mail Server+1

·

CVE-2026-35391

·

Published

2026-04-06

·

Updated

2026-04-06

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Bulwark Webmail versions prior to 1.4.11
Description Bulwark Webmail, a self-hosted webmail client for Stalwart Mail Server, is affected by an issue where the getClientIP() function in lib/admin/session.ts incorrectly trusts the first entry in the X-Forwarded-For header. This allows attackers to forge their source IP address, potentially bypassing IP-based rate limiting and forging audit log entries. The X-Forwarded-For header is fully controlled by the client.
Recommendations Update to Bulwark Webmail version 1.4.11 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35391
GHSA-7PJ2-232X-6698

Affected Products

Bulwark Webmail
Stalwart Mail Server