Executive brief
Bulwark Webmail, a self-hosted email client, failed to properly verify the authenticity of digitally signed emails. This allowed attackers to send fraudulent emails using untrusted or self-signed certificates that would appear to the recipient as having a valid, trusted signature. This could be used to conduct highly convincing phishing or impersonation attacks against users of the mail system.
Technical details
A vulnerability in Bulwark Webmail prior to version 1.4.11 was caused by improper certificate validation (CWE-295) in the S/MIME signature verification component. Specifically, the 'checkChain' parameter in 'lib/smime/smime-verify.ts' was set to false, bypassing the validation of the certificate trust chain. A remote attacker could send an email signed with a self-signed or otherwise untrusted certificate, and the webmail interface would incorrectly display it as having a valid signature. This allows for the spoofing of signed communications. The issue is resolved in version 1.4.11 by setting 'checkChain' to true.
Affected products
- Bulwark Webmail < 1.4.11
Timeline
- 2026-04-02: advisory: GitHub Security Advisory published
- 2026-04-06: disclosed: NVD publication date
- 2026-04-06: patched: Fix released in version 1.4.11