Algorithmic Complexity Flaw in Progressive Robot hMailServer
CVE-2026-107583
6.5MEDIUM
What is CVE-2026-107583?
An algorithmic complexity issue in the webmail's message view of the REST API in Progressive Robot hMailServer versions 6.3.2 to 6.3.5 leads to potential denial-of-service conditions. Remote unauthenticated attackers can exploit this flaw by sending specially crafted messages that cause the server to become unresponsive. The rendering process inefficiently handles multiple references to embedded images, significantly increasing resource consumption. This could overwhelm server resources, leaving legitimate users unable to access the webmail and administration functionalities.
Affected Version(s)
hMailServer 6.3.2 < 6.3.6
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Found in the hMailServer project's own security review (Progressive Robot Ltd)
