# Forward Email 3rd Party Audit

**URL:** https://discuss.privacyguides.net/t/forward-email-3rd-party-audit/40924
**Category:** General
**Created:** 2026-09-22T15:33:15Z
**Posts:** 5

## Post 1 by @securitybrahh — 2026-09-22T15:33:15Z

> **[pentest-report_forward-email-2.pdf](https://cure53.de/pentest-report_forward-email-2.pdf)**
>
> 696.87 KB

---

## Post 2 by @anonymous644 — 2026-09-22T15:44:14Z

I found it particularly interesting that Cure53 listed the CVE counts but never proved any of them reachable in the app.

> During the security assessment, the observation was made that several software packages leveraged outdated versions that are vulnerable to a host of security risks. Notably, the version information provided is based on data collected at the time of testing. Whether these vulnerabilities are exploitable entirely depends on how the relevant functionality is used in the targeted application at present.

I am not a security expert by any means so, this may all be normal for an audit. :person_shrugging:

---

## Post 3 by @ph00lt0 — 2026-09-22T16:45:10Z

Quite impressive they allowed for 25days of testing. A lot was found also… But seems at least they take it seriously. Positive sign.

---

## Post 4 by @jonah — 2026-09-22T17:38:28Z

I’ve never seen Cure53 tell someone to do the same audit again before lol

---

## Post 5 by @Expert4870 — 2026-09-22T17:42:47Z

The quote saying that is at the end if anyone’s wondering.

> Going forward, once all of the identified findings have been addressed, it is strongly recommended to conduct further penetration testing with the same scope, until the number and severity of vulnerabilities naturally decreases. This is expected, given the strong effort and reactiveness shown by the developers in both preparing this testing engagement, and in fixing vulnerabilities.
