Inefficient Complexity Vulnerability in Progressive Robot hMailServer by hMailServer
CVE-2026-107572
6.5MEDIUM
What is CVE-2026-107572?
The Progressive Robot hMailServer versions 6.2.24 to 6.3.5 exhibit inefficiencies in Sieve filter evaluation due to a backtracking descent algorithm. This vulnerability allows authenticated users to create Sieve scripts that can significantly degrade mail service performance. Patterns containing wildcards led to excessive processing times, effectively denying service by consuming server resources. As Sieve filters utilize a shared delivery thread pool, a single malicious account can craft tests that dimensions the server's ability to handle email, leading to prolonged mail delivery disruptions.
Affected Version(s)
hMailServer 6.2.24 < 6.3.6
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Found in the hMailServer project's own security review (Progressive Robot Ltd)
