CVE-2026-107583: Inefficient Algorithmic Complexity in hMailServer

Published Oct 8, 2026
·
Updated

Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. The route that renders a received message's HTML replaced each reference to an embedded image in place, with work that grew with the square of the number of references, and wrote the image out for every reference while counting it against its size limit only once. A message whose HTML refers to one small embedded image a very large number of times, opened in the webmail by its recipient, therefore keeps one of the listener's four worker threads busy for minutes and makes it build a document of gigabytes, so that a few such messages leave the HTTP listener unable to answer anybody.

Affected Software

1 affected component
Progressive Robot hMailServer>=6.3.2<=6.3.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Progressive Robot hMailServer to a version that resolves this vulnerability.

    Fixed in 6.3.6
  2. Configuration

    Lower the maximum message size to bound the cost of processing large HTML messages.

    hMailServer maximum message size = lower
  3. Configuration

    Leave the webmail offline store off so that processing is triggered only when a message is opened.

    hMailServer webmail offline store = off
  4. Configuration

    Keep the REST listener off by setting RestApiPort to 0.

    hMailServer REST listener RestApiPort = 0

Event History

Oct 8, 2026
CVE Published
via MITRE·11:49 AM
Data Sourced
via MITRE·11:49 AM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which services can be disrupted by a successful attack?

The HTTP listener can become unable to respond, affecting the webmail, administration console, and REST API. A few malicious messages can occupy its four worker threads.

2

What must happen for the denial of service to be triggered?

An attacker sends a message whose HTML repeatedly references the same small embedded image. The recipient must open that message in webmail, causing the message-rendering route to process the references.

3

Which installations are identified as affected?

Progressive Robot hMailServer versions 6.3.2 through 6.3.5 are identified as affected. The described impact is tied to rendering received HTML messages through the webmail message view.

4

What signs would indicate an attempted or successful trigger?

The triggering message contains a very large number of references to one embedded image. When opened in webmail, rendering can keep a listener worker thread busy for minutes and construct a document of gigabytes, followed by webmail, administration console, and REST API unavailability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203