CVE-2019-12269: Enigmail

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Enigmail before 2.0.11 allows PGP signature spoofing: for an inline PGP message, an attacker can cause the product to display a "correctly signed" message indication, but display different unauthenticated text.

Affected products

  • Enigmail Enigmail: before 2.0.11 (fixed in 2.0.11)

Published 2019-05-21. Last modified 2026-06-17.