CVE-2026-107586: Allocation of Resources Without Limits or Throttling in hMailServer

Published Oct 8, 2026
·
Updated

Uncontrolled eviction in the browser session table of the REST API in Progressive Robot hMailServer 6.2.28 through 6.3.5 allows a remote authenticated user to end other users' sessions. The table of browser sessions, shared by every account, the server administrator and support sessions, dropped its least recently used session whenever it was full, whoever it belonged to, and placed no limit on how many sessions one account could hold. A user who repeatedly signs in with their own mailbox password can therefore keep the table full and sign out every webmail and administration session that is idle for more than a short time, for as long as they continue.

Affected Software

1 affected component
Progressive Robot hMailServer>=6.2.28<=6.3.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Progressive Robot hMailServer to a version that resolves this vulnerability.

    Fixed in 6.3.6
  2. Compensating control

    Until upgrading, limit the rate of POST /api/v1/session per client at a reverse proxy in front of the listener.

  3. Compensating control

    Disable any account found signing in repeatedly, using the application log and device list to identify it.

Event History

Oct 8, 2026
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to session disruption?

Progressive Robot hMailServer versions 6.2.28 through 6.3.5 are affected where the REST API browser-session table is used. The shared table covers webmail account sessions as well as server administrator and support sessions.

2

What does an attacker need to exploit this issue?

The attacker needs valid mailbox credentials for any account and remote access to sign in repeatedly. No interaction from other users is required.

3

What is the practical impact?

An authenticated user can fill the shared browser-session table with their own sessions, causing least-recently-used sessions belonging to other users to be evicted. This can repeatedly sign out webmail, administration, and support users whose sessions have been idle for more than a short time.

4

What should be done if immediate remediation is not possible?

The provided data identifies the trigger as repeated sign-ins using a mailbox password. Monitor for or restrict abnormal repeated authentication activity from mailbox accounts until an update can be applied.

5

Is a fixed release identified?

Yes. The supplied release reference identifies hMailServer v6.3.6; affected versions are listed as 6.2.28 through 6.3.5.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203