Open Delivery Flaw in hMailServer by Progressive Robot
CVE-2026-107584
What is CVE-2026-107584?
The hMailServer versions 6.0.0 to 6.3.5 are susceptible to a vulnerability that allows attackers to interfere with the email delivery process. This flaw arises during the application of DANE, a TLS authentication method for securing SMTP delivery. If the DNSSEC resolver receives incomplete or malformed responses during the DNS lookup for TLSA or MX records, it may erroneously bypass security checks. Consequently, an attacker with the ability to manipulate DNS responses can disable DANE enforcement, potentially exposing sensitive messages to interception and modification by routing them to an untrusted destination. This vulnerability underscores the importance of secure configurations and robust DNS security practices.
Affected Version(s)
hMailServer 6.0.0 < 6.3.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
