IMAP Command Processing Vulnerability in hMailServer by Progressive Robot
CVE-2026-107581

6.5MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107581?

The hMailServer version 6.0.0 to 6.3.5 is susceptible to a critical vulnerability that affects how multiple IMAP commands are processed. The server processes these commands in a way that can lead to quadratic time complexity based on command length or the number of elements specified. This vulnerability enables a signed-in user to execute IMAP commands that disproportionately increase memory usage, resulting in denial of service for IMAP, SMTP, and POP3 services. This behavior occurs due to inefficiencies in the FETCH data-item parser and case-insensitive search algorithms, which can result in significant memory consumption as commands grow in size. Attackers can exploit this by sending long or complex commands, potentially leading to service interruptions.

Affected Version(s)

hMailServer 6.0.0 < 6.3.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found in the hMailServer project's own security review (Progressive Robot Ltd)
.