CVE-2026-107574: Inefficient Algorithmic Complexity in hMailServer
Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the mail services unavailable. Reading a JSON object kept the first of each duplicated member name by searching the members already read, so an object of N distinct member names cost O(N^2): 1 MB took 8.9 seconds and 4 MB took 300 seconds against the affected code. A remote attacker reaches the reader without an account by mailing a crafted TLS-RPT report (up to 16 MB after decompression) to a hosted domain's published report mailbox, which is read on a delivery thread; a few such reports hold every delivery thread (ten by default), so the server delivers no mail, local or outbound, for over an hour per report. A signed-in account reaches the same 16 MB body through the webmail's own REST routes, holding the REST API's own worker threads. Where no report mailbox is configured, the unauthenticated REST sign-in routes that read a JSON body are capped at 64 KB and are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
hMailServerto a version that resolves this vulnerability.Fixed in 6.3.6 - Configuration
Where domain reports are enabled, move the report mailbox off the hosted domain.
hMailServer TLS-RPT domain reports report mailbox location = off the hosted domain - Operational
Restart the hMailServer service to end a busy delivery thread.
Event History
Frequently Asked Questions
Which deployments are exposed to unauthenticated disruption?
A server is exposed without authentication when a hosted domain has a published TLS-RPT report mailbox. An attacker can send a crafted TLS-RPT report to that mailbox, where it is processed on a mail delivery thread.
Are the unauthenticated REST sign-in endpoints affected when no report mailbox is configured?
No. Where no report mailbox is configured, the unauthenticated REST sign-in routes that read JSON bodies are limited to 64 KB and are not affected.
What level of access does an attacker need to affect webmail processing?
A signed-in account can submit the same type of large JSON body through webmail REST routes. This consumes the REST API's worker threads rather than mail delivery threads.
How severe can the mail-delivery impact be in a default configuration?
A few crafted reports can occupy every delivery thread; the default is ten delivery threads. While those threads are held, the server may deliver no local or outbound mail for more than an hour per report.