Open Delivery Flaw in hMailServer by Progressive Robot
CVE-2026-107584

7.4HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107584?

The hMailServer versions 6.0.0 to 6.3.5 are susceptible to a vulnerability that allows attackers to interfere with the email delivery process. This flaw arises during the application of DANE, a TLS authentication method for securing SMTP delivery. If the DNSSEC resolver receives incomplete or malformed responses during the DNS lookup for TLSA or MX records, it may erroneously bypass security checks. Consequently, an attacker with the ability to manipulate DNS responses can disable DANE enforcement, potentially exposing sensitive messages to interception and modification by routing them to an untrusted destination. This vulnerability underscores the importance of secure configurations and robust DNS security practices.

Affected Version(s)

hMailServer 6.0.0 < 6.3.6

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Found in the hMailServer project's own security review (Progressive Robot Ltd)
.