CVE-2026-107583: Inefficient Algorithmic Complexity in hMailServer
Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. The route that renders a received message's HTML replaced each reference to an embedded image in place, with work that grew with the square of the number of references, and wrote the image out for every reference while counting it against its size limit only once. A message whose HTML refers to one small embedded image a very large number of times, opened in the webmail by its recipient, therefore keeps one of the listener's four worker threads busy for minutes and makes it build a document of gigabytes, so that a few such messages leave the HTTP listener unable to answer anybody.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progressive Robot hMailServerto a version that resolves this vulnerability.Fixed in 6.3.6 - Configuration
Lower the maximum message size to bound the cost of processing large HTML messages.
hMailServer maximum message size = lower - Configuration
Leave the webmail offline store off so that processing is triggered only when a message is opened.
hMailServer webmail offline store = off - Configuration
Keep the REST listener off by setting RestApiPort to 0.
hMailServer REST listener RestApiPort = 0
Event History
Frequently Asked Questions
Which services can be disrupted by a successful attack?
The HTTP listener can become unable to respond, affecting the webmail, administration console, and REST API. A few malicious messages can occupy its four worker threads.
What must happen for the denial of service to be triggered?
An attacker sends a message whose HTML repeatedly references the same small embedded image. The recipient must open that message in webmail, causing the message-rendering route to process the references.
Which installations are identified as affected?
Progressive Robot hMailServer versions 6.3.2 through 6.3.5 are identified as affected. The described impact is tied to rendering received HTML messages through the webmail message view.
What signs would indicate an attempted or successful trigger?
The triggering message contains a very large number of references to one embedded image. When opened in webmail, rendering can keep a listener worker thread busy for minutes and construct a document of gigabytes, followed by webmail, administration console, and REST API unavailability.