Sceawere

Vulnerability Detail

CVE-2026-107575UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

hMailServer SPF Macro Algorithmic Complexity

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
2h ago
Vendor
Progressive Robot Ltd
Product
hMailServer
Attack Type
CWE-407: Inefficient Algorithmic Complexity
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Inefficient algorithmic complexity in the SPF macro expansion of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to consume worker-thread time by publishing a crafted SPF record. RFC 7208 section 7.1 requires a name too long to look up to lose whole labels from the left; the server did this by removing one label at a time and copying the rest of the name each time, so the work grew with the square of the expansion. An attacker who publishes an SPF record for a domain they control, with a mechanism whose domain-spec expands through macros to a name far longer than 253 characters, makes the SPF check of a message from that domain take several seconds. The expansion is bounded by SPF's own per-term and per-macro limits, so the loss of availability is partial.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-08T12:17:15.333Z",
  "pubdate": "2026-10-08T12:17:15.333Z",
  "executiveSummary": "An algorithmic complexity vulnerability exists in the SPF macro expansion logic of Progressive Robot hMailServer versions 6.3.4 and 6.3.5. The issue stems from an inefficient string manipulation process during the expansion of domain names exceeding standard length requirements as defined in RFC 7208.\nThis vulnerability allows a remote, unauthenticated attacker to induce significant CPU exhaustion on the mail server. By publishing a maliciously crafted SPF record for a domain under their control, an attacker can trigger the vulnerable expansion mechanism when the server processes incoming mail from that domain. The resulting quadratic time complexity leads to prolonged worker-thread utilization, causing a partial denial-of-service (DoS) condition.\nThe risk is categorized as a resource exhaustion flaw that degrades system availability. Because the attack utilizes standard SPF mechanisms and per-term limits, it is difficult to distinguish from legitimate traffic without specific algorithmic fixes. The impact is limited to the exhaustion of server worker threads, effectively slowing down mail processing capabilities and impacting overall service throughput.",
  "technicalDetails": "The root cause of this vulnerability is an inefficient implementation of the SPF macro expansion process within Progressive Robot hMailServer. According to RFC 7208 section 7.1, when an SPF macro expansion results in a domain name exceeding 253 characters, the implementation is required to truncate the name by removing labels from the left side until the name complies with the length restriction. The vulnerable code implements this by iteratively removing one label at a time and performing a complete memory copy of the remaining string during every iteration.\nThe computational complexity of this operation is O(n^2), where 'n' represents the length of the expanded macro string. As the attacker provides a domain name that expands to a significantly excessive length, the server performs a disproportionately large number of memory allocation and copy operations for every processed email. This forces the server to spend several seconds per SPF check, tying up critical worker threads.\nThe exploitation flow begins when an attacker publishes a crafted SPF record in the DNS settings of a domain they control. This record includes a mechanism that utilizes SPF macros to generate a domain name string that surpasses the 253-character limit upon expansion. When an email originating from or claiming to be from the attacker's domain reaches the hMailServer, the server initiates an SPF check. The server attempts to resolve the macros defined in the SPF record and subsequently triggers the vulnerable string-pruning logic.\nBecause the server lacks an optimized approach to label removal, such as pointer manipulation or in-place modification, the system consumes excessive CPU cycles. An attacker can repeat this process across multiple concurrent connections to exhaust the pool of available worker threads, leading to a state of resource contention. While SPF limits on per-term and per-macro evaluations provide a hard cap on total processing, the sheer intensity of the quadratic complexity within these limits is sufficient to cause a partial denial-of-service on the mail transfer agent (MTA) component.\nAffected versions include Progressive Robot hMailServer 6.3.4 and 6.3.5. The vulnerability is triggered remotely without authentication, making it reachable by any entity capable of sending email to the server or triggering an SPF lookup on the targeted installation."
}
CVE-2026-107575: hMailServer SPF Macro Algorithmic Complexity (MEDIUM Severity, CVSS: 5.3) | Sceawere