Inefficient Algorithmic Complexity in hMailServer by Progressive Robot
CVE-2026-107576
What is CVE-2026-107576?
The hMailServer from Progressive Robot exhibits an inefficient algorithmic complexity in its inbound DKIM and ARC signature verification. This issue allows a remote attacker to potentially disrupt mail services by exploiting message headers with numerous fields or extensive folding. The flawed canonicalization processes delay header validation significantly, as the system faces challenges in handling headers with multiple signatures, leading to considerable resource consumption. Consequently, the mail server may become unavailable, impacting normal operations. The affected versions include 6.0.0 through 6.3.5. Immediate updates and rigorous configurations are recommended to mitigate possible threats.
Affected Version(s)
hMailServer 6.0.0 < 6.3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
