Sceawere

Vulnerability Detail

CVE-2026-107574UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

hMailServer Algorithmic Complexity Denial-of-Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
2h ago
Vendor
Progressive Robot Ltd
Product
hMailServer
Attack Type
CWE-407: Inefficient Algorithmic Complexity
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the mail services unavailable. Reading a JSON object kept the first of each duplicated member name by searching the members already read, so an object of N distinct member names cost O(N^2): 1 MB took 8.9 seconds and 4 MB took 300 seconds against the affected code. A remote attacker reaches the reader without an account by mailing a crafted TLS-RPT report (up to 16 MB after decompression) to a hosted domain's published report mailbox, which is read on a delivery thread; a few such reports hold every delivery thread (ten by default), so the server delivers no mail, local or outbound, for over an hour per report. A signed-in account reaches the same 16 MB body through the webmail's own REST routes, holding the REST API's own worker threads. Where no report mailbox is configured, the unauthenticated REST sign-in routes that read a JSON body are capped at 64 KB and are not affected.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-08T12:17:15.177Z",
  "pubdate": "2026-10-08T12:17:15.177Z",
  "executiveSummary": "Progressive Robot hMailServer is vulnerable to a remote denial-of-service (DoS) condition caused by inefficient algorithmic complexity within its JSON parsing implementation.\nThe vulnerability stems from an O(N^2) processing complexity when handling JSON objects containing duplicate member names, as the parser performs redundant linear scans of previously read members.\nAttackers can leverage this by submitting malformed JSON payloads, such as crafted TLS-RPT reports, to exhaust server worker threads. This results in the complete unavailability of mail delivery and webmail REST services.\nThe vulnerability affects both unauthenticated remote attackers—via mail submission to configured report mailboxes—and authenticated users interacting with the webmail REST API.\nGiven that default configurations allocate a limited number of worker threads, a small number of carefully crafted payloads can cause extended service outages exceeding one hour per request.\nThis vulnerability highlights a critical failure in input validation and parsing logic, potentially allowing an unauthenticated remote adversary to disrupt core infrastructure operations without requiring valid credentials.",
  "technicalDetails": "The root cause of this vulnerability is an inefficient implementation of JSON member resolution within the Progressive Robot hMailServer JSON reader. When parsing a JSON object, the implementation maintains an exhaustive list of members already processed. For every new member encountered, the reader performs a linear search through the existing list to ensure uniqueness, retaining only the first instance of any duplicated member name.\nThis design choice results in quadratic O(N^2) time complexity relative to the number of distinct member names (N). Performance benchmarks indicate significant processing latency: a 1 MB payload requires approximately 8.9 seconds to parse, while a 4 MB payload necessitates 300 seconds of sustained CPU utilization. Because these operations are executed within the context of the mail delivery thread or webmail worker thread, a single request can effectively hang a thread for the duration of the parsing process.\nThe attack flow for unauthenticated remote attackers utilizes the TLS-RPT reporting mechanism. An attacker sends an email containing a crafted, highly redundant JSON body (up to 16 MB after decompression) to a domain's published report mailbox. The mail delivery thread processes this input, triggering the inefficient search loop. Since hMailServer typically defaults to ten delivery threads, ten concurrent malicious reports will exhaust the entire thread pool, resulting in a total cessation of mail delivery services for the duration of the processing cycle.\nAuthenticated attackers exploit the same logic via webmail REST API routes that accept JSON bodies. By submitting the malformed payload to these routes, attackers can target the REST API worker threads, rendering webmail functionality unusable.\nWhile the vulnerability is restricted by the size of the payload, the 16 MB limit allowed for TLS-RPT reports is sufficiently large to facilitate a complete denial-of-service. Routes not configured to process large JSON inputs, such as standard unauthenticated REST sign-in routes, are restricted to 64 KB and remain unaffected by the O(N^2) complexity spike."
}
CVE-2026-107574: hMailServer Algorithmic Complexity Denial-of-Service (HIGH Severity, CVSS: 7.5) | Sceawere