CVE-2026-103011: Heap-based Buffer Overflow in hMailServer
Heap-based buffer overflow in the legacy Blowfish encryption routine (BlowFishEncryptor::Encode, called by EncryptToString) in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows an authenticated mailbox user to cause a denial of service (service crash), and possibly other unspecified impact. In 6.3.4 and 6.3.5, where the self-service REST API is enabled (it is off by default), the user does this remotely by adding a fetch account whose password is 129 to 247 characters long and not a multiple of 8, and then requesting their personal data export (GET /api/v1/me/export.zip), which encrypts that password with the legacy scheme. The same flaw is reachable on Windows by any local interactive user with no hMailServer credentials, through the COM method Utilities.BlowfishEncrypt, which checked no authentication. It is also reachable by every stored-secret write when ProtectStoredSecretsWithDPAPI is set to 0. For such a length, the routine's padding loop writes up to 7 zero bytes 2 to 232 bytes past the end of its 255-byte heap buffer. The ciphertext it returns is still correct.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
hMailServerto a version that resolves this vulnerability.Fixed in 6.3.6 - Configuration
Keep the REST API disabled by setting RestApiPort to 0, the default; alternatively, expose it only to trusted users.
hMailServer REST API RestApiPort = 0 - Configuration
Keep ProtectStoredSecretsWithDPAPI enabled by setting it to 1, the default.
hMailServer ProtectStoredSecretsWithDPAPI = 1 - Compensating control
Do not grant remote DCOM activation to the hMailServer AppID.
- Compensating control
Do not give untrusted people an interactive logon on the server.
Event History
Frequently Asked Questions
Which deployments are exposed to remote exploitation?
Remote exploitation requires hMailServer 6.3.4 or 6.3.5 with the self-service REST API enabled. The REST API is off by default, and exploitation also requires an authenticated mailbox user account.
What must an attacker do to trigger the crash through the REST API?
The attacker adds a fetch account with a password between 129 and 247 characters that is not a multiple of 8 characters long, then requests their personal data export at GET /api/v1/me/export.zip. The export process encrypts the password with the affected legacy routine.
Are systems without the REST API enabled still affected?
Yes. On Windows, any local interactive user can reach the vulnerable routine through the unauthenticated Utilities.BlowfishEncrypt COM method without hMailServer credentials. The flaw is also reached whenever stored secrets are written if ProtectStoredSecretsWithDPAPI is set to 0.
What is the known impact?
A mailbox user can cause a service crash, resulting in denial of service. The overflow can write up to 7 zero bytes beyond the 255-byte heap buffer; other impact is unspecified.
Which versions should be investigated for this issue?
The affected range is hMailServer 6.0.0 through 6.3.5. A release reference is provided for version 6.3.6.