CVE-2026-107582: Inefficient Algorithmic Complexity in hMailServer

Published Oct 8, 2026
·
Updated

Inefficient algorithmic complexity in the REST API (6.3.3 through 6.3.5) and the IMAP PREVIEW response (6.2.22 through 6.3.5) of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. To show a snippet of each message in a folder's message list, the server decoded the character entity references of a message that has an HTML part and no text part with a string replacement whose work grew with the square of their number. A received HTML-only message holding a very large number of entity references therefore keeps one of the listener's four worker threads busy for minutes or longer each time the recipient's webmail lists the folder, without the message being opened, so that a few such listings leave the HTTP listener unable to answer anybody. The IMAP PREVIEW response read such text the same way, holding an IMAP thread for each client that asks for the preview of such a message. The flaw is in the server's shared string class, whose replace and remove both ran in quadratic time.

Affected Software

1 affected component
Progressive Robot hMailServer>=6.3.3<=6.3.5, >=6.2.22<=6.3.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Progressive Robot hMailServer to a version that resolves this vulnerability.

    Fixed in 6.3.6
  2. Remove

    Remove the affected component from your environment.

    Remove the affected message over IMAP or POP3.

  3. Configuration

    Keep the REST listener off by setting RestApiPort to 0; 0 is the default.

    hMailServer RestApiPort = 0
  4. Configuration

    Lower the maximum message size to bound the processing cost of oversized HTML messages.

    hMailServer maximum message size = lower

Event History

Oct 8, 2026
CVE Published
via MITRE·11:48 AM
Data Sourced
via MITRE·11:48 AM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to the HTTP-based denial of service?

hMailServer versions 6.3.3 through 6.3.5 are affected through the REST API path. The impact can make webmail, the administration console, and the REST API unavailable when HTTP listener worker threads are exhausted.

2

Can an attacker exploit this without credentials or interaction from a user?

Yes. A remote unauthenticated attacker can send an HTML-only message containing a very large number of character entity references. Exploitation is triggered when the recipient's webmail lists the folder containing the message, even if the message is not opened.

3

What is affected through IMAP?

The IMAP PREVIEW response is affected in versions 6.2.22 through 6.3.5. Each client requesting a preview for a crafted message can occupy an IMAP thread while the server decodes the message content.

4

How can administrators identify potentially malicious messages?

Look for received messages with an HTML part but no text part and an unusually large number of HTML character entity references. Listing a folder containing such messages may cause prolonged worker-thread use and HTTP or IMAP responsiveness problems.

5

What can be done if updating is not immediately possible?

The provided information identifies the crafted-message condition but does not specify a complete mitigation. Administrators can investigate and remove or isolate suspicious HTML-only messages with very large numbers of entity references to reduce repeated triggering when folders are listed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203