Inefficient Complexity Vulnerability in Progressive Robot hMailServer by hMailServer
CVE-2026-107572

6.5MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107572?

The Progressive Robot hMailServer versions 6.2.24 to 6.3.5 exhibit inefficiencies in Sieve filter evaluation due to a backtracking descent algorithm. This vulnerability allows authenticated users to create Sieve scripts that can significantly degrade mail service performance. Patterns containing wildcards led to excessive processing times, effectively denying service by consuming server resources. As Sieve filters utilize a shared delivery thread pool, a single malicious account can craft tests that dimensions the server's ability to handle email, leading to prolonged mail delivery disruptions.

Affected Version(s)

hMailServer 6.2.24 < 6.3.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found in the hMailServer project's own security review (Progressive Robot Ltd)
.