Algorithmic Complexity Vulnerability in hMailServer REST API and IMAP
CVE-2026-107582
6.5MEDIUM
What is CVE-2026-107582?
The hMailServer has a vulnerability related to inefficient algorithmic complexity in its REST API and IMAP PREVIEW response functionalities. This flaw allows remote unauthenticated attackers to render the webmail, administration console, and REST API inaccessible by exploiting specific messages with HTML parts that contain numerous character entity references. When such a message is present, server resource allocation intensifies, leading to prolonged delays in response. As a result, the webmail and IMAP clients experience degraded service, potentially bringing the server's HTTP listener to a halt during folder message list requests.
Affected Version(s)
hMailServer 6.2.22-pre1 < 6.3.6
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Found in the hMailServer project's own security review (Progressive Robot Ltd)
