Inefficient Algorithmic Complexity in Progressive Robot hMailServer
CVE-2026-107580
6.5MEDIUM
What is CVE-2026-107580?
The Progressive Robot hMailServer, versions 6.0.0 to 6.3.5, suffers from an inefficiency in the decoding of message header fields. This flaw allows remote unauthenticated attackers to exploit the IMAP, SMTP, and POP3 services through crafted messages. When the server processes certain header values, the time taken increases significantly due to the algorithm's quadratic complexity, ultimately leading to service unavailability. This can occur during various actions such as folder searches and sorts, causing shared threads managing IMAP, SMTP, and POP3 responses to become unresponsive, resulting in denial of service.
Affected Version(s)
hMailServer 6.0.0 < 6.3.6
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Found in the hMailServer project's own security review (Progressive Robot Ltd)
