Sceawere
Vulnerability Detail
CVE-2026-107581UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
hMailServer Algorithmic Complexity Denial-of-Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 2h ago
- Vendor
- Progressive Robot Ltd
- Product
- hMailServer
- Attack Type
- CWE-407: Inefficient Algorithmic Complexity
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadratic in the command's length or in the number of elements it names, and can be made to hold memory out of proportion to a command. The FETCH data-item parser normalised a BODY[] section with a case-insensitive string replacement that copied the whole item per occurrence and split the item list by repeatedly copying the remainder of the command; the server's case-insensitive search compared a needle afresh at every position, so a long SEARCH TEXT key over a message cost the product of the two lengths; SEARCH message sets and the saved-result marker ($), SORT criteria, HEADER.FIELDS name lists and UID ranges were each read once per message rather than once per command; and a FETCH naming a message's sections very many times read and held every section in memory before sending any. An IMAP command may continue past one line through non-synchronizing literals, so one command can reach about eleven megabytes. The IMAP worker threads are a small pool shared with SMTP and POP3, so a signed-in user sending such commands can make the IMAP, SMTP and POP3 services stop responding (CWE-407) and can consume excessive memory (CWE-400).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-08T12:17:16.320Z",
"pubdate": "2026-10-08T12:17:16.320Z",
"executiveSummary": "hMailServer versions 6.0.0 through 6.3.5 contain multiple vulnerabilities related to inefficient algorithmic processing of IMAP commands. These issues facilitate CWE-400 (Uncontrolled Resource Consumption) and CWE-407 (Inefficient Algorithmic Complexity).\nA remote, authenticated attacker can exploit these flaws by submitting specifically crafted IMAP commands designed to trigger quadratic time complexity or excessive memory allocation. Because IMAP worker threads are shared with SMTP and POP3 services, the resource exhaustion caused by these malformed requests leads to a complete denial-of-service for all mail-related protocols.\nThe vulnerability is critical due to the ease with which an authenticated user can exhaust server resources, effectively halting mail delivery and retrieval operations. The attack requires a valid account session but does not necessitate elevated administrative privileges, making it a significant risk to mail server availability.",
"technicalDetails": "The vulnerability stems from inefficient parsing and processing logic within the hMailServer IMAP command handling implementation. Several components exhibit quadratic time complexity relative to input length or element counts, leading to resource exhaustion under heavy load.\nSpecific technical deficiencies identified include: 1) The FETCH data-item parser: This component performs case-insensitive string normalization using a method that copies the entire item per occurrence and repeatedly copies the remainder of the command list during parsing. 2) SEARCH command implementation: The server performs a needle-in-haystack comparison that re-evaluates the entire search string at every position, resulting in O(N*M) complexity where N and M are the lengths of the search key and the target message text. 3) Resource Management: Operations involving SEARCH message sets, the saved-result marker ($), SORT criteria, HEADER.FIELDS lists, and UID ranges are processed once per message rather than once per command, incurring massive overhead during mass-processing operations. 4) Memory Buffering: A FETCH request targeting numerous message sections forces the server to buffer all requested sections into memory before initiating transmission, facilitating memory exhaustion.\nAttack Flow: An attacker establishes an authenticated IMAP session and transmits a crafted command sequence. Given that IMAP commands can utilize non-synchronizing literals to extend beyond a single line, a single command can grow to approximately 11MB. By embedding complex, resource-heavy operations (such as multi-section FETCH or long-key SEARCH commands) within these long-form command strings, an attacker forces the server to perform disproportionate memory allocations and CPU-intensive parsing loops.\nExploitation Impact: Because the IMAP worker threads operate within a shared pool used by SMTP and POP3 services, the degradation of the IMAP parser directly impacts the availability of the entire mail server. The cumulative effect of these algorithmic inefficiencies is the starvation of worker threads, resulting in a system-wide denial-of-service where the server ceases to respond to any inbound or outbound mail traffic, effectively locking the system until the resource pressure is relieved or the service is restarted."
}