Sceawere

Vulnerability Detail

CVE-2026-107580UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

hMailServer Algorithmic Complexity Denial-of-Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
Progressive Robot Ltd
Product
hMailServer
Attack Type
CWE-407: Inefficient Algorithmic Complexity
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Inefficient algorithmic complexity in the decoding of message header fields in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the IMAP, SMTP and POP3 services, or the webmail, unavailable by sending a message. The server unfolded a decoded header value by finding each line break from the end of the value and removing it, moving the rest of the value each time, so its work grew with the square of the number of line breaks, and an RFC 2047 encoded word may decode to any number of them. A received message whose Subject or other header field holds such a value keeps a worker thread busy for minutes or longer each time the value is read: when the recipient's IMAP client searches, sorts or threads the folder by a header, when the webmail lists the folder, and, where configured, when a rule tests a header, a spam tag is added to the Subject or an abuse report is read during delivery. The IMAP worker threads are shared with SMTP and POP3, so a few such messages stop those services responding. The server's reading of a message header from its file also searched everything read so far after each 4,000 bytes, costing seconds for a header of tens of megabytes.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-08T12:17:16.123Z",
  "pubdate": "2026-10-08T12:17:16.123Z",
  "executiveSummary": "Progressive Robot hMailServer versions 6.0.0 through 6.3.5 are susceptible to a Denial-of-Service (DoS) vulnerability originating from inefficient algorithmic complexity during the decoding of message header fields. This flaw allows a remote, unauthenticated attacker to exhaust server resources by injecting specially crafted RFC 2047 encoded words within SMTP, IMAP, or POP3 message headers. The server's header-unfolding mechanism exhibits quadratic time complexity relative to the number of contained line breaks, while the header-reading logic imposes high latency on large files due to repeated redundant scanning. Successful exploitation forces worker threads into prolonged execution states, effectively stalling service responsiveness for all users. Given that hMailServer shares worker threads across SMTP, IMAP, and POP3 protocols, a minimal number of malicious messages can induce a complete system-wide service outage. The vulnerability poses a significant risk to availability, as it requires no prior authentication or administrative privileges to execute, relying only on the delivery of a single crafted email message.",
  "technicalDetails": "The vulnerability is rooted in two distinct inefficiencies within the hMailServer header processing engine: a quadratic-time unfolding algorithm and a non-optimal header scanning procedure.\nFirst, the header-unfolding mechanism is designed to remove line breaks from decoded header values. The implementation iterates backwards through the decoded string to locate line breaks and performs an in-place memory shift for the remainder of the string every time a break is found. Because RFC 2047 encoded words can be manipulated to expand into an arbitrary number of line breaks, the computational cost of this process scales at O(n^2) where n is the number of line breaks. A crafted message header containing a high density of these encoded breaks causes the server to spend excessive CPU cycles performing these repeated memory move operations.\nSecond, the header-parsing logic incorporates a scanning mechanism that re-scans the entire buffer read thus far after every 4,000 bytes of data processed. For headers reaching tens of megabytes in size, this redundant verification results in a linear-logarithmic overhead that leads to significant latency, potentially blocking threads for seconds per individual header.\nThe attack flow begins when an unauthenticated attacker sends a message containing the malicious header fields (such as 'Subject') to the target server via SMTP. The vulnerability is triggered during subsequent access to these headers. Because hMailServer threads are shared across protocols, the impact is systemic. Trigger points include: 1) Incoming SMTP delivery, if rules are configured to test headers or add spam tags; 2) IMAP folder operations, such as sorting, searching, or threading; 3) Webmail client folder listing; and 4) Reading abuse reports. When a thread is occupied by the complex decoding process, it becomes unavailable for concurrent requests. Since the thread pool is limited, the consumption of threads by a single malicious message prevents the server from responding to legitimate traffic, resulting in a total denial-of-service for the IMAP, SMTP, POP3, and webmail interfaces. The vulnerability affects hMailServer 6.0.0 through 6.3.5."
}
CVE-2026-107580: hMailServer Algorithmic Complexity Denial-of-Service (MEDIUM Severity, CVSS: 6.5) | Sceawere