Inefficient Algorithmic Complexity in Progressive Robot hMailServer
CVE-2026-107580

6.5MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107580?

The Progressive Robot hMailServer, versions 6.0.0 to 6.3.5, suffers from an inefficiency in the decoding of message header fields. This flaw allows remote unauthenticated attackers to exploit the IMAP, SMTP, and POP3 services through crafted messages. When the server processes certain header values, the time taken increases significantly due to the algorithm's quadratic complexity, ultimately leading to service unavailability. This can occur during various actions such as folder searches and sorts, causing shared threads managing IMAP, SMTP, and POP3 responses to become unresponsive, resulting in denial of service.

Affected Version(s)

hMailServer 6.0.0 < 6.3.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found in the hMailServer project's own security review (Progressive Robot Ltd)
.