Sceawere

Vulnerability Detail

CVE-2026-107582UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

hMailServer Algorithmic Denial-of-Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
Progressive Robot Ltd
Product
hMailServer
Attack Type
CWE-407: Inefficient Algorithmic Complexity
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Inefficient algorithmic complexity in the REST API (6.3.3 through 6.3.5) and the IMAP PREVIEW response (6.2.22 through 6.3.5) of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. To show a snippet of each message in a folder's message list, the server decoded the character entity references of a message that has an HTML part and no text part with a string replacement whose work grew with the square of their number. A received HTML-only message holding a very large number of entity references therefore keeps one of the listener's four worker threads busy for minutes or longer each time the recipient's webmail lists the folder, without the message being opened, so that a few such listings leave the HTTP listener unable to answer anybody. The IMAP PREVIEW response read such text the same way, holding an IMAP thread for each client that asks for the preview of such a message. The flaw is in the server's shared string class, whose replace and remove both ran in quadratic time.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-08T12:17:16.480Z",
  "pubdate": "2026-10-08T12:17:16.480Z",
  "executiveSummary": "This vulnerability involves an inefficient algorithmic complexity issue within the REST API and the IMAP PREVIEW response mechanism of Progressive Robot hMailServer.\nThe flaw stems from a quadratic-time complexity implementation within the server's shared string class during the decoding of HTML character entity references.\nA remote unauthenticated attacker can exploit this by sending a specially crafted HTML-only email containing a high volume of character entity references.\nWhen the server attempts to generate a message preview for the folder list, the resource-intensive decoding process consumes worker threads, leading to a state of Denial-of-Service (DoS).\nAffected components include the webmail interface, administration console, and the REST API. Because the processing occurs upon folder listing rather than message opening, the service becomes unavailable to all users once the limited pool of worker threads is exhausted.\nThis represents a significant availability risk as it requires no authentication and can be triggered by any entity capable of sending an email to the server.",
  "technicalDetails": "The core of the vulnerability resides in the server's shared string class, specifically within the string replacement and removal functions. These functions exhibit O(n^2) algorithmic complexity, meaning the processing time grows quadratically in proportion to the number of operations performed.\nIn the context of Progressive Robot hMailServer versions 6.3.3 through 6.3.5 (REST API) and 6.2.22 through 6.3.5 (IMAP PREVIEW), the server performs automatic decoding of HTML character entity references when displaying message snippets in folder listings. This behavior is triggered for messages containing an HTML part but lacking an equivalent text part.\nThe attack vector involves a remote unauthenticated attacker transmitting an HTML-only email payload containing a disproportionately large number of character entity references. When the victim user accesses their webmail or an IMAP client requests a PREVIEW response for the mailbox containing this payload, the server initiates the flawed decoding routine.\nThe step-by-step exploitation flow is as follows: 1) The attacker sends a malicious message to an hMailServer account; 2) The victim accesses the folder list via webmail or issues an IMAP PREVIEW command; 3) The server's shared string class attempts to normalize the HTML content for snippet generation; 4) The O(n^2) replacement logic consumes excessive CPU cycles; 5) A dedicated worker thread becomes locked in this loop for minutes or longer; 6) By repeating this process across a few requests, the server's four-thread listener limit is reached.\nBecause the thread depletion occurs at the listener level, the webmail interface, administrative console, and REST API functionality are rendered unavailable to legitimate users. The impact is a complete exhaustion of service resources, effectively paralyzing the server's ability to respond to concurrent incoming requests. The vulnerability is particularly severe because the trigger action occurs during standard mailbox navigation, requiring zero user interaction with the malicious message content itself."
}
CVE-2026-107582: hMailServer Algorithmic Denial-of-Service (MEDIUM Severity, CVSS: 6.5) | Sceawere