CVE-2026-107574: Inefficient Algorithmic Complexity in hMailServer

Published Oct 8, 2026
·
Updated

Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the mail services unavailable. Reading a JSON object kept the first of each duplicated member name by searching the members already read, so an object of N distinct member names cost O(N^2): 1 MB took 8.9 seconds and 4 MB took 300 seconds against the affected code. A remote attacker reaches the reader without an account by mailing a crafted TLS-RPT report (up to 16 MB after decompression) to a hosted domain's published report mailbox, which is read on a delivery thread; a few such reports hold every delivery thread (ten by default), so the server delivers no mail, local or outbound, for over an hour per report. A signed-in account reaches the same 16 MB body through the webmail's own REST routes, holding the REST API's own worker threads. Where no report mailbox is configured, the unauthenticated REST sign-in routes that read a JSON body are capped at 64 KB and are not affected.

Affected Software

1 affected component
Progressive Robot hMailServer

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade hMailServer to a version that resolves this vulnerability.

    Fixed in 6.3.6
  2. Configuration

    Where domain reports are enabled, move the report mailbox off the hosted domain.

    hMailServer TLS-RPT domain reports report mailbox location = off the hosted domain
  3. Operational

    Restart the hMailServer service to end a busy delivery thread.

Event History

Oct 8, 2026
CVE Published
via MITRE·11:46 AM
Data Sourced
via MITRE·11:46 AM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to unauthenticated disruption?

A server is exposed without authentication when a hosted domain has a published TLS-RPT report mailbox. An attacker can send a crafted TLS-RPT report to that mailbox, where it is processed on a mail delivery thread.

2

Are the unauthenticated REST sign-in endpoints affected when no report mailbox is configured?

No. Where no report mailbox is configured, the unauthenticated REST sign-in routes that read JSON bodies are limited to 64 KB and are not affected.

3

What level of access does an attacker need to affect webmail processing?

A signed-in account can submit the same type of large JSON body through webmail REST routes. This consumes the REST API's worker threads rather than mail delivery threads.

4

How severe can the mail-delivery impact be in a default configuration?

A few crafted reports can occupy every delivery thread; the default is ten delivery threads. While those threads are held, the server may deliver no local or outbound mail for more than an hour per report.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203