CVE-2026-107581: Inefficient Algorithmic Complexity in hMailServer

Published Oct 8, 2026
·
Updated

Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadratic in the command's length or in the number of elements it names, and can be made to hold memory out of proportion to a command. The FETCH data-item parser normalised a BODY[] section with a case-insensitive string replacement that copied the whole item per occurrence and split the item list by repeatedly copying the remainder of the command; the server's case-insensitive search compared a needle afresh at every position, so a long SEARCH TEXT key over a message cost the product of the two lengths; SEARCH message sets and the saved-result marker ($), SORT criteria, HEADER.FIELDS name lists and UID ranges were each read once per message rather than once per command; and a FETCH naming a message's sections very many times read and held every section in memory before sending any. An IMAP command may continue past one line through non-synchronizing literals, so one command can reach about eleven megabytes. The IMAP worker threads are a small pool shared with SMTP and POP3, so a signed-in user sending such commands can make the IMAP, SMTP and POP3 services stop responding (CWE-407) and can consume excessive memory (CWE-400).

Affected Software

1 affected component
Progressive Robot hMailServer>=6.0.0<=6.3.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Progressive Robot hMailServer to a version that resolves this vulnerability.

    Fixed in 6.3.6
  2. Compensating control

    Restrict IMAP access to trusted accounts and networks to reduce who can send the resource-intensive commands.

Event History

Oct 8, 2026
CVE Published
via MITRE·11:47 AM
Data Sourced
via MITRE·11:47 AM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

What access does an attacker need?

The attacker needs a signed-in IMAP account. No user interaction is required after authentication.

2

Which services can be disrupted?

The affected IMAP worker threads are shared with SMTP and POP3. Exhausting the small worker pool can cause IMAP, SMTP, and POP3 services to stop responding.

3

What versions should be updated?

Progressive Robot hMailServer 6.0.0 through 6.3.5 are affected. Version 6.3.6 is referenced as the release containing the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203