Sceawere
Vulnerability Detail
CVE-2026-103649UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
hMailServer Linux Thread Exhaustion
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Progressive Robot Ltd
- Product
- hMailServer
- Attack Type
- CWE-1088: Synchronous Access of Remote Resource without Timeout
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Missing network timeouts in the Linux builds of Progressive Robot hMailServer 6.3.0 through 6.3.5 allow a remote attacker to hold server threads indefinitely and so stop outbound mail delivery (denial of service). The server set its socket timeouts in the form Windows takes, which Linux refuses, and its HTTPS clients read without a deadline, so a peer that accepts a connection and then sends nothing held the waiting thread for as long as the connection stayed open. The MTA-STS policy fetch, enabled by default, is made during outbound delivery to mta-sts.<recipient domain>, so anyone who can make the server deliver mail to a domain they control - for example as the envelope sender of a message that bounces - can hold delivery threads until outbound delivery stops. The same flaw affects the DANE TLSA query, the OAuth2 token request, the ACME client, and the ManageSieve and metrics listeners, which a silent client stops from serving anyone else. Windows builds are not affected.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-08T11:16:43.093Z",
"pubdate": "2026-10-08T11:16:43.093Z",
"executiveSummary": "Progressive Robot hMailServer versions 6.3.0 through 6.3.5 for Linux are susceptible to a Denial of Service (DoS) vulnerability originating from improper socket timeout configuration. The defect manifests because the application attempts to apply Windows-specific socket timeout parameters to the Linux networking stack, which are either misinterpreted or ignored. This results in network operations—including HTTPS client requests, MTA-STS policy fetches, DANE TLSA queries, OAuth2 token requests, ACME client operations, and ManageSieve/metrics listeners—proceeding without a defined deadline. An unauthenticated remote attacker can exploit this by initiating a connection and deliberately withholding data transmission. Because the server threads remain in a permanent wait state, the thread pool becomes exhausted, effectively halting outbound mail delivery and blocking service availability for legitimate users. This vulnerability is specific to Linux builds and does not affect Windows deployments. The lack of robust timeout enforcement represents a critical failure in resource management, enabling remote attackers to disrupt mail server infrastructure without requiring special privileges or authentication.",
"technicalDetails": "The root cause of this vulnerability lies in the platform-incompatible implementation of socket I/O timeouts within the hMailServer codebase. When ported to Linux, the application continues to define socket timeouts using parameters and mechanisms specifically structured for the Windows API. The Linux networking stack fails to recognize these parameters, causing the underlying socket operations to default to an infinite timeout period. Consequently, any network-bound function that initiates an HTTPS request or listens for incoming traffic does not implement an operational deadline for peer response.\nThe attack flow leverages the default enablement of the MTA-STS policy fetch. An attacker can trigger a server-side request by causing the hMailServer instance to send mail to a domain under their control (e.g., through an email bounce or a crafted envelope sender). Upon receiving the connection request from the hMailServer MTA-STS client, the attacker accepts the TCP handshake but refuses to send any application-layer data. Because the server-side socket lacks a timeout, the thread assigned to that connection enters a 'blocked' or 'waiting' state indefinitely. By repeating this process across multiple threads, the attacker reaches the server's thread concurrency limit.\nThis behavior extends beyond the MTA-STS fetch to other critical components: DANE TLSA query resolution, OAuth2 token request cycles, ACME client interactions, and the ManageSieve and metrics listeners. In each instance, a silent or malicious peer can hold a server thread captive. Once the thread pool is fully exhausted, the server can no longer spawn new threads to process outbound mail delivery, perform authentication, or respond to administrative queries, resulting in a persistent Denial of Service.\nThe vulnerability requires no authentication and can be triggered remotely. The payload behavior is passive; it does not require malicious code execution but rather the absence of traffic, which is sufficient to maintain the connection lock. The post-exploitation impact is a total cessation of outbound mail processing and administrative listener services. The server remains in this unresponsive state until the exhausted threads are released or the service is restarted, rendering the mail server completely incapable of fulfilling its primary functional duties until remediation occurs."
}