Inefficient Algorithm in Progressive Robot hMailServer Affects Mail Services
CVE-2026-107577

7.5HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107577?

A vulnerability in Progressive Robot hMailServer versions 6.0.0 to 6.3.5 arises from an inefficient algorithmic complexity in the MIME processing of incoming messages. This flaw allows an unauthenticated attacker to disrupt mail services by sending a specially crafted message. The vulnerability occurs when a MIME header parameter, such as a Content-Disposition with an empty value directly followed by a semicolon, leads to a non-terminating loop. This loop consumes worker thread resources until the server is restarted. Additionally, scenarios involving excessive RFC 2047 encoded words or many header fields can significantly degrade server performance, impacting IMAP, SMTP, and POP3 connections, as well as REST API interactions.

Affected Version(s)

hMailServer 6.0.0 < 6.3.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found in the hMailServer project's own security review (Progressive Robot Ltd)
.