CVE-2026-107586: Allocation of Resources Without Limits or Throttling in hMailServer
Uncontrolled eviction in the browser session table of the REST API in Progressive Robot hMailServer 6.2.28 through 6.3.5 allows a remote authenticated user to end other users' sessions. The table of browser sessions, shared by every account, the server administrator and support sessions, dropped its least recently used session whenever it was full, whoever it belonged to, and placed no limit on how many sessions one account could hold. A user who repeatedly signs in with their own mailbox password can therefore keep the table full and sign out every webmail and administration session that is idle for more than a short time, for as long as they continue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progressive Robot hMailServerto a version that resolves this vulnerability.Fixed in 6.3.6 - Compensating control
Until upgrading, limit the rate of POST /api/v1/session per client at a reverse proxy in front of the listener.
- Compensating control
Disable any account found signing in repeatedly, using the application log and device list to identify it.
Event History
Frequently Asked Questions
Which deployments are exposed to session disruption?
Progressive Robot hMailServer versions 6.2.28 through 6.3.5 are affected where the REST API browser-session table is used. The shared table covers webmail account sessions as well as server administrator and support sessions.
What does an attacker need to exploit this issue?
The attacker needs valid mailbox credentials for any account and remote access to sign in repeatedly. No interaction from other users is required.
What is the practical impact?
An authenticated user can fill the shared browser-session table with their own sessions, causing least-recently-used sessions belonging to other users to be evicted. This can repeatedly sign out webmail, administration, and support users whose sessions have been idle for more than a short time.
What should be done if immediate remediation is not possible?
The provided data identifies the trigger as repeated sign-ins using a mailbox password. Monitor for or restrict abnormal repeated authentication activity from mailbox accounts until an update can be applied.
Is a fixed release identified?
Yes. The supplied release reference identifies hMailServer v6.3.6; affected versions are listed as 6.2.28 through 6.3.5.