Sceawere

Vulnerability Detail

CVE-2026-107572UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

hMailServer Sieve Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
Progressive Robot Ltd
Product
hMailServer
Attack Type
CWE-1333: Inefficient Regular Expression Complexity
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Inefficient complexity in the Sieve filter evaluation of Progressive Robot hMailServer 6.2.24 through 6.3.5 allows an authenticated account holder to make the mail services unavailable with their own filter. A ':matches' pattern was matched by a backtracking descent whose time grew with the matched value's length raised to the number of wildcards, so a pattern such as '*a*a*a*b' over 800 characters took 44 seconds; and 'deleteheader' erased the fields it removed one at a time, so removing many fields of one name over a message's header cost O(N^2) (80,000 fields took 18.8 seconds). Sieve filters run on the small, shared delivery thread pool, so an account holder whose active script does this, fed a few messages they can send themselves, empties the pool and stops delivery for the whole server. The script is the account holder's own and cannot be set for another user.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-08T12:17:14.870Z",
  "pubdate": "2026-10-08T12:17:14.870Z",
  "executiveSummary": "Progressive Robot hMailServer versions 6.2.24 through 6.3.5 contain two distinct algorithmic complexity vulnerabilities within the Sieve filter evaluation engine. These flaws facilitate Denial of Service (DoS) attacks by enabling an authenticated attacker to exhaust shared delivery thread resources.\nThe primary vulnerabilities involve catastrophic backtracking in regex-like pattern matching and quadratic time complexity during header deletion operations. By crafting malicious Sieve filter scripts, an authenticated user can force the mail service to consume excessive CPU cycles and time for every processed message.\nBecause the server utilizes a small, shared thread pool for Sieve processing, a single malicious user can effectively starve the service of resources, leading to a complete halt of mail delivery for all users on the server. The attack is restricted to the authenticated user's own scripts, but the impact is global, affecting the availability of the entire messaging infrastructure. This vulnerability represents a significant risk to service availability and uptime, specifically targeting the resource management architecture of the mail server's delivery pipeline.",
  "technicalDetails": "The root cause of the vulnerability lies in inefficient algorithmic handling within the Sieve filter engine, specifically concerning pattern matching and header manipulation functions. The engine suffers from catastrophic backtracking during the evaluation of ':matches' patterns. When processing patterns containing multiple wildcards, the execution time grows exponentially relative to the matched value's length and the number of wildcards. For instance, an 800-character string against a pattern like '*a*a*a*b' can trigger a 44-second evaluation delay.\nAdditionally, the 'deleteheader' function implements an O(N^2) complexity algorithm. When removing multiple instances of a specific header field, the engine performs individual deletions rather than optimized bulk processing. Empirical testing demonstrates that deleting 80,000 header fields incurs a latency of approximately 18.8 seconds per message.\nThe exploitation flow begins with an authenticated attacker creating a Sieve filter script containing the computationally expensive operations described above. Once the script is active, the attacker triggers the filter by sending a sequence of specially crafted emails to their own account. Each incoming message forces the hMailServer delivery thread to enter the high-latency state associated with the inefficient regex backtracking or the nested deletion loops.\nThe critical impact stems from the server's architectural design, which utilizes a small, shared thread pool for all Sieve filter executions. Because the delivery threads are blocked for extended periods while processing these resource-heavy scripts, the pool quickly becomes exhausted. Once the thread pool is depleted, the server is unable to process any further mail delivery requests for any user, resulting in a system-wide Denial of Service.\nAffected versions include hMailServer 6.2.24 through 6.3.5. This vulnerability is constrained to the authenticated user's own scripts, meaning an attacker cannot modify or inject scripts into other users' accounts. However, no special administrative privileges are required to create the malicious script, provided the user has standard account access. The attack is effectively a self-inflicted resource exhaustion that leverages the server's shared-resource architecture to impact the global availability of the mail platform."
}
CVE-2026-107572: hMailServer Sieve Denial of Service (MEDIUM Severity, CVSS: 6.5) | Sceawere