Sceawere
Vulnerability Detail
CVE-2026-107584UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
hMailServer DANE Fail-Open Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.4
- Creation Date
- 2h ago
- Vendor
- Progressive Robot Ltd
- Product
- hMailServer
- Attack Type
- CWE-636: Not Failing Securely ('Failing Open')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Progressive Robot hMailServer 6.0.0 through 6.3.5 fails open when applying DANE (RFC 7672) to outbound SMTP delivery. The server's validating DNSSEC resolver treated a TLSA or MX lookup that did not complete (no answer, SERVFAIL, a malformed reply), an answer without the requested records and without an NSEC/NSEC3 proof of their absence, and an answer whose records carried no applicable RRSIG as if the recipient domain were unsigned, and from 6.2.19 it also delivered to mail exchangers taken from an unvalidated MX lookup that the DNSSEC-validated MX record set did not name. An attacker who can drop, forge or strip DNS answers on the path to the server's resolver, at the resolver, or between the resolver and the recipient domain's name servers, and who holds an active position on the SMTP path, can thereby disable DANE for a DNSSEC-signed recipient domain and cause messages to be delivered in cleartext or to a host of the attacker's choosing with an arbitrary certificate, where they can be read and modified.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.4",
"pubDate": "2026-10-08T12:17:16.787Z",
"pubdate": "2026-10-08T12:17:16.787Z",
"executiveSummary": "Progressive Robot hMailServer versions 6.0.0 through 6.3.5 contain a critical security flaw involving the improper implementation of DANE (RFC 7672) for outbound SMTP delivery. The vulnerability manifests as a 'fail-open' condition during DNSSEC-validated lookups.\nWhen the server encounters incomplete, malformed, or missing DNSSEC records (such as failed TLSA/MX lookups or missing RRSIG proofs), it incorrectly defaults to a non-DANE, cleartext delivery state rather than aborting the connection. Additionally, versions starting from 6.2.19 exhibit further logic errors where mail is routed to unvalidated MX records that contradict authenticated DNSSEC-validated sets.\nThis vulnerability allows an attacker positioned on the network path—capable of intercepting or manipulating DNS queries—to effectively strip DANE protections from recipient domains that are otherwise DNSSEC-signed. Consequently, sensitive email traffic can be downgraded to cleartext, or redirected to an attacker-controlled host presenting arbitrary certificates. This enables full interception, modification, or exposure of outbound communications. The flaw represents a significant breakdown in the secure delivery chain, undermining the integrity and confidentiality guarantees intended by DANE deployment.\nExploitation requires the attacker to hold an active position on the SMTP path and the ability to influence DNS resolution responses, effectively bypassing the security controls designed to prevent man-in-the-middle attacks.",
"technicalDetails": "The vulnerability resides within the outbound SMTP delivery logic of hMailServer 6.0.0 through 6.3.5, specifically concerning the interaction between the application and the configured DNSSEC-validating resolver. The root cause is a failure to enforce strict security policy adherence when the DNSSEC validation state is indeterminate or when critical security indicators are absent.\nIn a secure DANE implementation, any failure in the acquisition or validation of TLSA records for a domain that mandates DNSSEC must result in a connection termination to prevent downgrade attacks. hMailServer deviates from this by failing open. Specifically, if a lookup results in no answer, a SERVFAIL, a malformed response, or an answer that lacks the required RRSIG chains or TLSA records, the server treats the destination domain as if it were unsigned (non-DANE).\nThe attack flow follows a Man-in-the-Middle (MitM) paradigm. An attacker situated between the hMailServer and the DNS resolver, or between the resolver and the target authoritative name servers, can surgically drop or spoof DNS responses. By forcing a SERVFAIL or providing a 'no data' response without proper NSEC/NSEC3 authenticated denial-of-existence, the attacker tricks the hMailServer into bypassing DANE checks.\nBeginning with version 6.2.19, the vulnerability includes an additional logic error regarding MX record handling. Even when DNSSEC-validated MX records are successfully retrieved, the server is susceptible to delivering mail to mail exchangers retrieved from unvalidated MX lookups that do not match the authorized record set. This allows an attacker to manipulate the mail exchanger destination.\nOnce the DANE policy is bypassed, the mail delivery proceeds as a standard SMTP session without TLS authentication or certificate pinning. The attacker can then: 1) Perform a protocol downgrade to cleartext to intercept data; 2) Present a fraudulent certificate for a domain of their choosing to perform a MitM attack, decrypting, reading, and potentially altering the email content before forwarding it to the legitimate recipient. The vulnerability requires no authentication or special privileges on the target server, as the exploitation occurs via network-level manipulation of DNS and SMTP traffic flow."
}