Sceawere

Vulnerability Detail

CVE-2026-103011UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

hMailServer Blowfish Heap Overflow

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Progressive Robot Ltd
Product
hMailServer
Attack Type
CWE-122: Heap-based Buffer Overflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Heap-based buffer overflow in the legacy Blowfish encryption routine (BlowFishEncryptor::Encode, called by EncryptToString) in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows an authenticated mailbox user to cause a denial of service (service crash), and possibly other unspecified impact. In 6.3.4 and 6.3.5, where the self-service REST API is enabled (it is off by default), the user does this remotely by adding a fetch account whose password is 129 to 247 characters long and not a multiple of 8, and then requesting their personal data export (GET /api/v1/me/export.zip), which encrypts that password with the legacy scheme. The same flaw is reachable on Windows by any local interactive user with no hMailServer credentials, through the COM method Utilities.BlowfishEncrypt, which checked no authentication. It is also reachable by every stored-secret write when ProtectStoredSecretsWithDPAPI is set to 0. For such a length, the routine's padding loop writes up to 7 zero bytes 2 to 232 bytes past the end of its 255-byte heap buffer. The ciphertext it returns is still correct.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-08T11:16:42.270Z",
  "pubdate": "2026-10-08T11:16:42.270Z",
  "executiveSummary": "This vulnerability is a heap-based buffer overflow residing within the legacy Blowfish encryption routine used by Progressive Robot hMailServer versions 6.0.0 through 6.3.5.\nThe flaw allows authenticated mailbox users or local interactive users to trigger a memory corruption event, leading to a service crash (Denial of Service) or potential arbitrary code execution.\nThe vulnerability is exposed through multiple vectors: the REST API (if enabled), the local COM interface (Utilities.BlowfishEncrypt), and internal stored-secret write operations when DPAPI protection is disabled.\nExploitation requires providing a specifically crafted input string (129 to 247 characters) that fails to meet the 8-byte alignment requirement for the Blowfish algorithm.\nSuccessful exploitation results in an out-of-bounds write of up to 7 zero bytes beyond the allocated 255-byte heap buffer, corrupting adjacent heap memory.\nThe risk level is elevated due to the local COM interface's lack of authentication, which permits exploitation by any local user on the system regardless of hMailServer privileges.",
  "technicalDetails": "The vulnerability exists in the BlowFishEncryptor::Encode function, which serves as the backend for the EncryptToString method. The root cause is a boundary calculation error within the legacy encryption padding logic.\nWhen the input data is not a multiple of the 8-byte block size required by the Blowfish algorithm, the routine attempts to apply PKCS-style or similar padding. The implementation fails to properly validate the remaining buffer space before performing the write operation.\nSpecifically, when processing input strings between 129 and 247 characters, the padding loop incorrectly calculates the destination buffer offset, leading to an out-of-bounds write of up to 7 zero bytes at an offset ranging from 2 to 232 bytes past the fixed 255-byte heap allocation.\nThe attack flow varies based on the exposure vector. In the REST API scenario (versions 6.3.4 and 6.3.5), an attacker adds a fetch account with a malicious password length and triggers a personal data export request (GET /api/v1/me/export.zip). This forces the application to pass the malformed password into the vulnerable BlowFishEncryptor::Encode function.\nFor local exploitation, the Utilities.BlowfishEncrypt COM method provides a direct, unauthenticated interface to the vulnerable routine. Any interactive user on the host system can invoke this method, triggering the overflow without needing valid mail server credentials.\nAdditionally, if the ProtectStoredSecretsWithDPAPI setting is set to 0, the server utilizes this vulnerable routine to encrypt stored secrets. Consequently, any process or user capable of triggering a secret write operation can induce the heap overflow.\nWhile the ciphertext returned by the function remains technically correct, the resulting heap corruption impacts the stability of the hMailServer process. By overwriting heap metadata or adjacent objects, an attacker can manipulate application memory, leading to an immediate crash or creating conditions suitable for more advanced exploitation techniques such as control flow hijacking or information disclosure."
}
CVE-2026-103011: hMailServer Blowfish Heap Overflow (MEDIUM Severity, CVSS: 6.5) | Sceawere