Product
canarymail canary mail
2 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-65318
CVE-2021-26911
<= 5.1.40
When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-
all versions
core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.