CVE-2026-107576: Inefficient Algorithmic Complexity in hMailServer
Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the mail services unavailable by sending a message. Building the canonical header and choosing the header fields named in a signature's h= tag took time growing with the square of the message's header: the 'simple' canonicalisation prepended each continuation line of a folded field to the lines already gathered, and both canonicalisations searched the gathered fields from the bottom for each h= name and erased the match from the middle of the list. A message whose header holds very many fields, or a field folded over very many lines, with a DKIM-Signature the attacker signs for a domain they control, keeps a worker thread busy for tens of seconds per signature; up to ten signatures are evaluated per message by each of the DKIM and DMARC tests, on the threads that serve delivery and SMTP.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progressive Robot hMailServerto a version that resolves this vulnerability.Fixed in 6.3.6 - Configuration
Lower the maximum message size to bound the cost until upgrading to hMailServer 6.3.6.
hMailServer maximum message size
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service issue?
Progressive Robot hMailServer versions 6.0.0 through 6.3.5 are affected when processing inbound mail with DKIM or ARC signature verification. The costly work runs on threads serving delivery and SMTP, so repeated malicious messages can reduce mail-service availability.
What does an attacker need to send to trigger the problem?
An unauthenticated remote attacker can send a message with an unusually large number of header fields or a header field folded across many lines, along with a DKIM-Signature for a domain they control. No account or user interaction is required.
How severe can the resource consumption be per malicious message?
A crafted signature can keep a worker thread busy for tens of seconds. Up to ten signatures may be evaluated per message by each of the DKIM and DMARC tests, increasing the opportunity to exhaust threads handling SMTP and delivery.
What version resolves the issue?
The affected range ends at version 6.3.5, and the provided release reference is for hMailServer v6.3.6.