CVE-2026-107576: Inefficient Algorithmic Complexity in hMailServer

Published Oct 8, 2026
·
Updated

Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the mail services unavailable by sending a message. Building the canonical header and choosing the header fields named in a signature's h= tag took time growing with the square of the message's header: the 'simple' canonicalisation prepended each continuation line of a folded field to the lines already gathered, and both canonicalisations searched the gathered fields from the bottom for each h= name and erased the match from the middle of the list. A message whose header holds very many fields, or a field folded over very many lines, with a DKIM-Signature the attacker signs for a domain they control, keeps a worker thread busy for tens of seconds per signature; up to ten signatures are evaluated per message by each of the DKIM and DMARC tests, on the threads that serve delivery and SMTP.

Affected Software

1 affected component
Progressive Robot hMailServer>=6.0.0<=6.3.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Progressive Robot hMailServer to a version that resolves this vulnerability.

    Fixed in 6.3.6
  2. Configuration

    Lower the maximum message size to bound the cost until upgrading to hMailServer 6.3.6.

    hMailServer maximum message size

Event History

Oct 8, 2026
CVE Published
via MITRE·11:46 AM
Data Sourced
via MITRE·11:46 AM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this denial-of-service issue?

Progressive Robot hMailServer versions 6.0.0 through 6.3.5 are affected when processing inbound mail with DKIM or ARC signature verification. The costly work runs on threads serving delivery and SMTP, so repeated malicious messages can reduce mail-service availability.

2

What does an attacker need to send to trigger the problem?

An unauthenticated remote attacker can send a message with an unusually large number of header fields or a header field folded across many lines, along with a DKIM-Signature for a domain they control. No account or user interaction is required.

3

How severe can the resource consumption be per malicious message?

A crafted signature can keep a worker thread busy for tens of seconds. Up to ten signatures may be evaluated per message by each of the DKIM and DMARC tests, increasing the opportunity to exhaust threads handling SMTP and delivery.

4

What version resolves the issue?

The affected range ends at version 6.3.5, and the provided release reference is for hMailServer v6.3.6.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203