Executive brief
Bulwark Webmail is a self-hosted email client. A security flaw allows attackers to fake their location by spoofing their IP address. This can be used to bypass security protections like login rate limiting, making it easier for attackers to guess passwords or hide their tracks in system logs.
Technical details
A vulnerability exists in the getClientIP() function within lib/admin/session.ts of Bulwark Webmail. The application incorrectly trusts the leftmost entry of the X-Forwarded-For HTTP header, which is entirely client-controlled. By providing a forged IP address in this header, a remote attacker can bypass IP-based rate limiting mechanisms, facilitating brute-force attacks against the administrative login interface. Additionally, this allows for the forgery of audit log entries, masking the true origin of malicious activity. The issue is resolved in version 1.4.11 by switching to rightmost header parsing and introducing a configurable trusted proxy depth.
Affected products
- Bulwark Webmail < 1.4.11
Timeline
- 2026-04-02: advisory: GitHub Security Advisory published
- 2026-04-06: disclosed: CVE published
- 2026-04-06: patched: Fixed in version 1.4.11