CVE-2026-107581: Inefficient Algorithmic Complexity in hMailServer
Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadratic in the command's length or in the number of elements it names, and can be made to hold memory out of proportion to a command. The FETCH data-item parser normalised a BODY[] section with a case-insensitive string replacement that copied the whole item per occurrence and split the item list by repeatedly copying the remainder of the command; the server's case-insensitive search compared a needle afresh at every position, so a long SEARCH TEXT key over a message cost the product of the two lengths; SEARCH message sets and the saved-result marker ($), SORT criteria, HEADER.FIELDS name lists and UID ranges were each read once per message rather than once per command; and a FETCH naming a message's sections very many times read and held every section in memory before sending any. An IMAP command may continue past one line through non-synchronizing literals, so one command can reach about eleven megabytes. The IMAP worker threads are a small pool shared with SMTP and POP3, so a signed-in user sending such commands can make the IMAP, SMTP and POP3 services stop responding (CWE-407) and can consume excessive memory (CWE-400).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progressive Robot hMailServerto a version that resolves this vulnerability.Fixed in 6.3.6 - Compensating control
Restrict IMAP access to trusted accounts and networks to reduce who can send the resource-intensive commands.
Event History
Frequently Asked Questions
What access does an attacker need?
The attacker needs a signed-in IMAP account. No user interaction is required after authentication.
Which services can be disrupted?
The affected IMAP worker threads are shared with SMTP and POP3. Exhausting the small worker pool can cause IMAP, SMTP, and POP3 services to stop responding.
What versions should be updated?
Progressive Robot hMailServer 6.0.0 through 6.3.5 are affected. Version 6.3.6 is referenced as the release containing the fix.