Inefficient Algorithm in Progressive Robot hMailServer Affects Mail Services
CVE-2026-107577
What is CVE-2026-107577?
A vulnerability in Progressive Robot hMailServer versions 6.0.0 to 6.3.5 arises from an inefficient algorithmic complexity in the MIME processing of incoming messages. This flaw allows an unauthenticated attacker to disrupt mail services by sending a specially crafted message. The vulnerability occurs when a MIME header parameter, such as a Content-Disposition with an empty value directly followed by a semicolon, leads to a non-terminating loop. This loop consumes worker thread resources until the server is restarted. Additionally, scenarios involving excessive RFC 2047 encoded words or many header fields can significantly degrade server performance, impacting IMAP, SMTP, and POP3 connections, as well as REST API interactions.
Affected Version(s)
hMailServer 6.0.0 < 6.3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
