Inefficient Algorithm Impacting hMailServer by Progressive Robot
CVE-2026-107574
What is CVE-2026-107574?
The hMailServer by Progressive Robot is vulnerable due to an inefficient algorithmic complexity in its JSON reader, allowing remote unauthenticated attackers to render mail services unavailable. When an attacker exploits this vulnerability by sending a specially crafted TLS-RPT report to a domain's report mailbox, the server's response time degrades significantly, leading to mail delivery issues. This occurs when the JSON object processing delays—where the algorithm's time complexity increases quadratically with the number of distinct member names—overload the server. In certain conditions, this can prevent all mail delivery, both local and outbound, for extended periods. Users are encouraged to review their configurations and apply necessary updates to maintain server security.
Affected Version(s)
hMailServer 6.2.28 < 6.3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
