Heap-based Buffer Overflow in hMailServer by Progressive Robot
CVE-2026-103011

6.5MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-103011?

A heap-based buffer overflow vulnerability exists in the legacy Blowfish encryption routine of hMailServer versions 6.0.0 to 6.3.5. This flaw allows an authenticated mailbox user to trigger a denial of service through specific malicious actions, particularly when utilizing certain functionalities of the self-service REST API. Users manipulating password lengths beyond 128 characters can exploit this vulnerability, leading to a potential crash of the service. Additionally, local interactive users on Windows can exploit this without requiring hMailServer credentials, as the method used does not enforce authentication checks. The impact includes not only service disruption but possibilities for other unforeseen consequences due to unchecked buffer operations.

Affected Version(s)

hMailServer 6.0.0 < 6.3.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found in the hMailServer project's own code review (Progressive Robot Ltd)
.