Junglewise Threat Intelligence

CVE-2026-35389: Bulwark Webmail improper certificate validation in S/MIME verification

CVE-2026-35389 · Severity: high · CVSS 7.5 · Published 2026-04-06

Technologies: Bulwark Webmail.

Executive brief

Bulwark Webmail, a self-hosted email client, failed to properly verify the authenticity of digitally signed emails. This allowed attackers to send fraudulent emails using untrusted or self-signed certificates that would appear to the recipient as having a valid, trusted signature. This could be used to conduct highly convincing phishing or impersonation attacks against users of the mail system.

Technical details

A vulnerability in Bulwark Webmail prior to version 1.4.11 was caused by improper certificate validation (CWE-295) in the S/MIME signature verification component. Specifically, the 'checkChain' parameter in 'lib/smime/smime-verify.ts' was set to false, bypassing the validation of the certificate trust chain. A remote attacker could send an email signed with a self-signed or otherwise untrusted certificate, and the webmail interface would incorrectly display it as having a valid signature. This allows for the spoofing of signed communications. The issue is resolved in version 1.4.11 by setting 'checkChain' to true.

Affected products

  • Bulwark Webmail < 1.4.11

Timeline

  • 2026-04-02: advisory: GitHub Security Advisory published
  • 2026-04-06: disclosed: NVD publication date
  • 2026-04-06: patched: Fix released in version 1.4.11

References