Heap-based Buffer Overflow in hMailServer by Progressive Robot
CVE-2026-103011
What is CVE-2026-103011?
A heap-based buffer overflow vulnerability exists in the legacy Blowfish encryption routine of hMailServer versions 6.0.0 to 6.3.5. This flaw allows an authenticated mailbox user to trigger a denial of service through specific malicious actions, particularly when utilizing certain functionalities of the self-service REST API. Users manipulating password lengths beyond 128 characters can exploit this vulnerability, leading to a potential crash of the service. Additionally, local interactive users on Windows can exploit this without requiring hMailServer credentials, as the method used does not enforce authentication checks. The impact includes not only service disruption but possibilities for other unforeseen consequences due to unchecked buffer operations.
Affected Version(s)
hMailServer 6.0.0 < 6.3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
