Sceawere
Vulnerability Detail
CVE-2026-107583UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
hMailServer Algorithmic Denial of Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 2h ago
- Vendor
- Progressive Robot Ltd
- Product
- hMailServer
- Attack Type
- CWE-407: Inefficient Algorithmic Complexity
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. The route that renders a received message's HTML replaced each reference to an embedded image in place, with work that grew with the square of the number of references, and wrote the image out for every reference while counting it against its size limit only once. A message whose HTML refers to one small embedded image a very large number of times, opened in the webmail by its recipient, therefore keeps one of the listener's four worker threads busy for minutes and makes it build a document of gigabytes, so that a few such messages leave the HTTP listener unable to answer anybody.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-08T12:17:16.633Z",
"pubdate": "2026-10-08T12:17:16.633Z",
"executiveSummary": "A critical algorithmic complexity vulnerability exists within the Progressive Robot hMailServer REST API and webmail interface (versions 6.3.2 through 6.3.5). The flaw involves inefficient resource handling during the rendering of HTML-formatted messages containing multiple references to embedded images.\nA remote unauthenticated attacker can trigger a resource exhaustion condition by crafting a malicious email containing a high volume of references to a single embedded image. When a recipient opens this email via the webmail interface, the server's processing logic performs redundant operations, causing quadratic growth in memory and CPU utilization.\nThe primary impact is a Denial of Service (DoS) affecting the webmail interface, the administration console, and the REST API. Because the processing tasks consume worker thread availability, the HTTP listener becomes saturated, effectively rendering the entire management and mail access infrastructure unresponsive. This vulnerability poses a significant risk to service availability and does not require prior authentication or elevated privileges, making it a severe threat to public-facing mail server installations.",
"technicalDetails": "The vulnerability resides in the message rendering logic of the Progressive Robot hMailServer REST API, specifically in the component responsible for parsing and rendering HTML content for message display. The root cause is an inefficient algorithmic implementation where the application replaces references to embedded images within an HTML document using a quadratic time complexity function, denoted as O(n^2) relative to the number of references.\nWhen a user opens an email, the server iterates through the HTML content to process embedded image tags. The implementation writes the image data to the output buffer for every single reference found in the HTML. Critically, while the system checks the total image size against a configured limit only once, the rendering engine repeatedly appends the image data to the document stream for each unique reference instance.\nAn attacker exploits this by constructing an HTML payload that references a single small embedded image thousands of times. The attack flow proceeds as follows: 1) The attacker transmits a crafted email to a target recipient; 2) The recipient triggers the vulnerability by viewing the message via the webmail interface; 3) The server's REST API/webmail rendering component initiates the flawed replacement routine; 4) The application attempts to build a resulting document in memory that expands to gigabytes in size due to the redundant image injection; 5) The processing thread responsible for this task becomes locked for minutes, continuously consuming CPU cycles and system memory.\nBecause the server utilizes a limited pool of worker threads (specifically four in the default configuration), a small number of such malicious requests can exhaust the entire thread pool. Once all threads are occupied by these resource-intensive rendering tasks, the HTTP listener ceases to accept or process further requests. This results in total unavailability of the webmail, the administration console, and the REST API. The vulnerability is exploitable by remote, unauthenticated attackers, as the initial message injection does not require server-side interaction, only the target's subsequent viewing of the payload."
}