CVE-2026-107582: Inefficient Algorithmic Complexity in hMailServer
Inefficient algorithmic complexity in the REST API (6.3.3 through 6.3.5) and the IMAP PREVIEW response (6.2.22 through 6.3.5) of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. To show a snippet of each message in a folder's message list, the server decoded the character entity references of a message that has an HTML part and no text part with a string replacement whose work grew with the square of their number. A received HTML-only message holding a very large number of entity references therefore keeps one of the listener's four worker threads busy for minutes or longer each time the recipient's webmail lists the folder, without the message being opened, so that a few such listings leave the HTTP listener unable to answer anybody. The IMAP PREVIEW response read such text the same way, holding an IMAP thread for each client that asks for the preview of such a message. The flaw is in the server's shared string class, whose replace and remove both ran in quadratic time.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progressive Robot hMailServerto a version that resolves this vulnerability.Fixed in 6.3.6 - Remove
Remove the affected component from your environment.
Remove the affected message over IMAP or POP3.
- Configuration
Keep the REST listener off by setting RestApiPort to 0; 0 is the default.
hMailServer RestApiPort = 0 - Configuration
Lower the maximum message size to bound the processing cost of oversized HTML messages.
hMailServer maximum message size = lower
Event History
Frequently Asked Questions
Which deployments are exposed to the HTTP-based denial of service?
hMailServer versions 6.3.3 through 6.3.5 are affected through the REST API path. The impact can make webmail, the administration console, and the REST API unavailable when HTTP listener worker threads are exhausted.
Can an attacker exploit this without credentials or interaction from a user?
Yes. A remote unauthenticated attacker can send an HTML-only message containing a very large number of character entity references. Exploitation is triggered when the recipient's webmail lists the folder containing the message, even if the message is not opened.
What is affected through IMAP?
The IMAP PREVIEW response is affected in versions 6.2.22 through 6.3.5. Each client requesting a preview for a crafted message can occupy an IMAP thread while the server decodes the message content.
How can administrators identify potentially malicious messages?
Look for received messages with an HTML part but no text part and an unusually large number of HTML character entity references. Listing a folder containing such messages may cause prolonged worker-thread use and HTTP or IMAP responsiveness problems.
What can be done if updating is not immediately possible?
The provided information identifies the crafted-message condition but does not specify a complete mitigation. Administrators can investigate and remove or isolate suspicious HTML-only messages with very large numbers of entity references to reduce repeated triggering when folders are listed.