Junglewise Threat Intelligence

CVE-2026-35390: Bulwark Webmail Cross-Site Scripting via CSP Misconfiguration

CVE-2026-35390 · Severity: medium · CVSS 5.4 · Published 2026-04-06

Technologies: Bulwark Webmail.

Executive brief

Bulwark Webmail is a self-hosted email client. A security flaw in its built-in proxy allowed malicious scripts in emails to run in a user's browser because security protections were set to 'report-only' mode instead of being enforced. This could allow an attacker to steal login sessions or perform unauthorized actions on behalf of a user who opens a malicious email.

Technical details

A vulnerability exists in Bulwark Webmail's reverse proxy (proxy.ts) where the Content-Security-Policy-Report-Only header was used instead of the enforcing Content-Security-Policy header. This misconfiguration effectively disabled CSP protections, allowing Cross-Site Scripting (XSS) attacks to proceed unblocked. An attacker can exploit this by sending a crafted HTML email containing malicious scripts. If a user views the email, the script executes in the context of the webmail application, enabling session token theft or unauthorized state-changing actions. The issue is resolved in version 1.4.11 by switching to an enforcing CSP header.

Affected products

  • Bulwark Webmail < 1.4.11

Timeline

  • 2026-04-02: advisory: GitHub Security Advisory published
  • 2026-04-06: disclosed: CVE published to NVD
  • 2026-04-06: patched: Fix released in version 1.4.11

References