IMAP Command Processing Vulnerability in hMailServer by Progressive Robot
CVE-2026-107581
What is CVE-2026-107581?
The hMailServer version 6.0.0 to 6.3.5 is susceptible to a critical vulnerability that affects how multiple IMAP commands are processed. The server processes these commands in a way that can lead to quadratic time complexity based on command length or the number of elements specified. This vulnerability enables a signed-in user to execute IMAP commands that disproportionately increase memory usage, resulting in denial of service for IMAP, SMTP, and POP3 services. This behavior occurs due to inefficiencies in the FETCH data-item parser and case-insensitive search algorithms, which can result in significant memory consumption as commands grow in size. Attackers can exploit this by sending long or complex commands, potentially leading to service interruptions.
Affected Version(s)
hMailServer 6.0.0 < 6.3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
