CVE-2026-103011: Heap-based Buffer Overflow in hMailServer

Published Oct 8, 2026
·
Updated

Heap-based buffer overflow in the legacy Blowfish encryption routine (BlowFishEncryptor::Encode, called by EncryptToString) in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows an authenticated mailbox user to cause a denial of service (service crash), and possibly other unspecified impact. In 6.3.4 and 6.3.5, where the self-service REST API is enabled (it is off by default), the user does this remotely by adding a fetch account whose password is 129 to 247 characters long and not a multiple of 8, and then requesting their personal data export (GET /api/v1/me/export.zip), which encrypts that password with the legacy scheme. The same flaw is reachable on Windows by any local interactive user with no hMailServer credentials, through the COM method Utilities.BlowfishEncrypt, which checked no authentication. It is also reachable by every stored-secret write when ProtectStoredSecretsWithDPAPI is set to 0. For such a length, the routine's padding loop writes up to 7 zero bytes 2 to 232 bytes past the end of its 255-byte heap buffer. The ciphertext it returns is still correct.

Affected Software

1 affected component
Progressive Robot hMailServer>=6.0.0<=6.3.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade hMailServer to a version that resolves this vulnerability.

    Fixed in 6.3.6
  2. Configuration

    Keep the REST API disabled by setting RestApiPort to 0, the default; alternatively, expose it only to trusted users.

    hMailServer REST API RestApiPort = 0
  3. Configuration

    Keep ProtectStoredSecretsWithDPAPI enabled by setting it to 1, the default.

    hMailServer ProtectStoredSecretsWithDPAPI = 1
  4. Compensating control

    Do not grant remote DCOM activation to the hMailServer AppID.

  5. Compensating control

    Do not give untrusted people an interactive logon on the server.

Event History

Oct 8, 2026
CVE Published
via MITRE·10:53 AM
Data Sourced
via MITRE·10:53 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to remote exploitation?

Remote exploitation requires hMailServer 6.3.4 or 6.3.5 with the self-service REST API enabled. The REST API is off by default, and exploitation also requires an authenticated mailbox user account.

2

What must an attacker do to trigger the crash through the REST API?

The attacker adds a fetch account with a password between 129 and 247 characters that is not a multiple of 8 characters long, then requests their personal data export at GET /api/v1/me/export.zip. The export process encrypts the password with the affected legacy routine.

3

Are systems without the REST API enabled still affected?

Yes. On Windows, any local interactive user can reach the vulnerable routine through the unauthenticated Utilities.BlowfishEncrypt COM method without hMailServer credentials. The flaw is also reached whenever stored secrets are written if ProtectStoredSecretsWithDPAPI is set to 0.

4

What is the known impact?

A mailbox user can cause a service crash, resulting in denial of service. The overflow can write up to 7 zero bytes beyond the 255-byte heap buffer; other impact is unspecified.

5

Which versions should be investigated for this issue?

The affected range is hMailServer 6.0.0 through 6.3.5. A release reference is provided for version 6.3.6.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203