Sceawere
Vulnerability Detail
CVE-2026-107577UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
hMailServer MIME Processing Denial-of-Service
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 2h ago
- Vendor
- Progressive Robot Ltd
- Product
- hMailServer
- Attack Type
- CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Inefficient algorithmic complexity and a non-terminating loop in the MIME processing of received messages in Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote unauthenticated attacker to make the mail services unavailable by sending a message. Removing a MIME header parameter whose value is empty and directly followed by a semicolon (for example a Content-Disposition with 'filename=a.bat; filename=;') entered a loop that never terminates, holding a worker thread at full load until the server is restarted; this is reached when the attachment blocker renames a blocked attachment or a filename is set over the REST API. Separately, decoding a header field that holds many RFC 2047 encoded words of an encoding other than base64 or quoted-printable, removing a parameter with many RFC 2231 continuations, and deleting many header fields of one name each took time growing with the square of the message, on the small thread pools that serve IMAP, SMTP and POP3 connections, delivery and the REST API.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-08T12:17:15.630Z",
"pubdate": "2026-10-08T12:17:15.630Z",
"executiveSummary": "Progressive Robot hMailServer versions 6.0.0 through 6.3.5 contain multiple vulnerabilities in the MIME processing engine that facilitate Denial-of-Service (DoS) attacks.\nThe vulnerabilities stem from inefficient algorithmic complexity and non-terminating loop conditions within the message parsing logic.\nA remote, unauthenticated attacker can trigger these conditions by sending a maliciously crafted email message.\nSuccessful exploitation results in the exhaustion of worker thread resources, causing the SMTP, IMAP, POP3, and REST API services to become unavailable, requiring a full server restart to restore functionality.\nThe risk is critical due to the ease of exploitation, as no authentication or specific privileges are required to send the triggering payloads to the mail service.",
"technicalDetails": "The vulnerability is primarily located within the MIME parsing and header processing components of hMailServer. It manifests through two distinct but related technical flaws: an infinite loop and quadratic algorithmic complexity.\nThe non-terminating loop occurs during the processing of MIME header parameters. Specifically, when the parser encounters a parameter with an empty value that is immediately followed by a semicolon (e.g., 'filename=a.bat; filename=;'), the logic enters an infinite loop. This scenario is triggered during the attachment-blocking process or via filename manipulation through the REST API. Because the loop consumes 100% of a worker thread, the server's limited thread pool becomes quickly saturated, leading to a complete service outage.\nThe second issue involves algorithmic complexity exhaustion. The parser exhibits O(n^2) scaling when performing three specific operations: decoding header fields containing large quantities of non-standard RFC 2047 encoded words (excluding base64 or quoted-printable), processing headers with excessive RFC 2231 continuations, and parsing messages containing a high volume of duplicate header fields. Because these operations grow quadratically relative to the message size, an attacker can submit large, specially crafted messages that force the server to expend excessive CPU cycles on a single request.\nThe attack flow for the infinite loop involves an unauthenticated attacker injecting a crafted MIME header into an SMTP transmission. Upon reaching the internal processing stage where the attachment blocker evaluates filenames, the parser encounters the malformed parameter sequence, triggering the deadlock. Once a thread is captured, it is effectively removed from the available pool, preventing the system from processing incoming mail, user authentications, or API requests.\nThe quadratic complexity flaw allows an attacker to perform a resource-exhaustion attack by flooding the server with messages that mandate intensive parsing operations. Given the small size of the thread pools allocated for SMTP, IMAP, POP3, and the REST API, the cumulative effect of these operations leads to thread starvation and system-wide service failure. The vulnerability affects all core hMailServer services that utilize the vulnerable MIME processing logic, exposing the system to remote disruption from any network-reachable source."
}