Sceawere

Vulnerability Detail

CVE-2026-107576UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

hMailServer Inefficient DKIM Complexity

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
2h ago
Vendor
Progressive Robot Ltd
Product
hMailServer
Attack Type
CWE-407: Inefficient Algorithmic Complexity
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the mail services unavailable by sending a message. Building the canonical header and choosing the header fields named in a signature's h= tag took time growing with the square of the message's header: the 'simple' canonicalisation prepended each continuation line of a folded field to the lines already gathered, and both canonicalisations searched the gathered fields from the bottom for each h= name and erased the match from the middle of the list. A message whose header holds very many fields, or a field folded over very many lines, with a DKIM-Signature the attacker signs for a domain they control, keeps a worker thread busy for tens of seconds per signature; up to ten signatures are evaluated per message by each of the DKIM and DMARC tests, on the threads that serve delivery and SMTP.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-08T12:17:15.487Z",
  "pubdate": "2026-10-08T12:17:15.487Z",
  "executiveSummary": "Progressive Robot hMailServer 6.0.0 through 6.3.5 is susceptible to a Denial of Service (DoS) vulnerability due to inefficient algorithmic complexity in its DKIM and ARC signature verification logic.\nThe vulnerability stems from quadratic time complexity during the header canonicalization and signature verification process, allowing an unauthenticated remote attacker to exhaust system resources.\nBy sending a maliciously crafted email with a large number of header fields or deeply folded fields, an attacker can force the mail server to perform excessive computations.\nThis impacts service availability by saturating worker threads responsible for SMTP delivery and message processing.\nSince the vulnerability does not require authentication, it poses a significant risk to mail server availability, as the resource consumption per signature can keep threads occupied for extended durations.",
  "technicalDetails": "The root cause of this vulnerability is an algorithmic inefficiency within the DKIM/ARC signature verification engine of hMailServer 6.0.0 through 6.3.5. Specifically, the canonicalization process and the selection of header fields specified in the 'h=' tag of the DKIM-Signature display O(n^2) complexity relative to the number of header lines.\nThe 'simple' canonicalization implementation incorrectly prepends continuation lines of folded headers to the existing list, leading to redundant data manipulation. Furthermore, when verifying headers specified in the 'h=' tag, the application performs a reverse-search through the gathered field list for each signature tag. Upon finding a match, it performs an in-place deletion from the middle of the list, necessitating a memory shift or pointer realignment for the remaining elements.\nAn attacker can exploit this by crafting a message with a high volume of header fields or a single header field folded over an excessive number of lines. When the server processes such a message containing a DKIM-Signature controlled by the attacker, the aforementioned inefficient search and deletion operations result in high CPU utilization.\nThe attack flow follows these steps: 1. The attacker composes an SMTP message containing either an excessively long, folded header or a large number of arbitrary header fields. 2. The attacker includes a DKIM-Signature tag that they control. 3. Upon receipt, the hMailServer delivery/SMTP worker thread initiates DKIM and DMARC verification. 4. The canonicalization logic triggers, forcing the thread to spend tens of seconds performing list manipulation for every signature evaluated. 5. Because hMailServer evaluates up to ten signatures per message for both DKIM and DMARC, a single maliciously crafted email can block critical worker threads for several minutes.\nThe vulnerability is exposed via the SMTP protocol, requiring no authentication. The post-exploitation impact is a persistent Denial of Service, as repeated submission of such payloads can exhaust the pool of available worker threads, rendering the mail service unable to process legitimate incoming or outgoing mail."
}
CVE-2026-107576: hMailServer Inefficient DKIM Complexity (HIGH Severity, CVSS: 7.5) | Sceawere