CVE-2026-103011
Received Received - Intake

Heap-based Buffer Overflow in hMailServer

Vulnerability report for CVE-2026-103011, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Heap-based buffer overflow in the legacy Blowfish encryption routine (BlowFishEncryptor::Encode, called by EncryptToString) in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows an authenticated mailbox user to cause a denial of service (service crash), and possibly other unspecified impact. In 6.3.4 and 6.3.5, where the self-service REST API is enabled (it is off by default), the user does this remotely by adding a fetch account whose password is 129 to 247 characters long and not a multiple of 8, and then requesting their personal data export (GET /api/v1/me/export.zip), which encrypts that password with the legacy scheme. The same flaw is reachable on Windows by any local interactive user with no hMailServer credentials, through the COM method Utilities.BlowfishEncrypt, which checked no authentication. It is also reachable by every stored-secret write when ProtectStoredSecretsWithDPAPI is set to 0. For such a length, the routine's padding loop writes up to 7 zero bytes 2 to 232 bytes past the end of its 255-byte heap buffer. The ciphertext it returns is still correct.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap-based buffer overflow in the Blowfish encryption routine of hMailServer versions 6.0.0 through 6.3.5. An authenticated mailbox user can trigger a denial of service by causing a service crash. In versions 6.3.4 and 6.3.5, if the self-service REST API is enabled, a remote user can exploit this by adding a fetch account with a password of 129 to 247 characters not divisible by 8, then requesting a personal data export. The flaw also affects Windows systems via the COM method without authentication.

Detection Guidance

This vulnerability is triggered by specific actions like adding a fetch account with a password of 129 to 247 characters not divisible by 8, then requesting a personal data export via the REST API. Check hMailServer logs for unusual password lengths or failed encryption operations. For Windows systems, monitor calls to the COM method Utilities.BlowfishEncrypt.

Impact Analysis

This vulnerability can cause a denial of service by crashing the hMailServer service. It may also allow unauthorized access to sensitive data or enable further exploitation depending on the system configuration. Local users without credentials can exploit it on Windows systems, and stored secrets may be compromised if ProtectStoredSecretsWithDPAPI is disabled.

Compliance Impact

This vulnerability could lead to unauthorized access or disclosure of sensitive data, which may violate GDPR's data protection requirements or HIPAA's security rules for protected health information. Organizations using affected hMailServer versions may face compliance violations and potential penalties if exploited.

Mitigation Strategies

Upgrade hMailServer to a version beyond 6.3.5 where this flaw is patched. Disable the self-service REST API if not needed. Ensure ProtectStoredSecretsWithDPAPI is set to 1. Restrict local interactive user access to the BlowfishEncrypt COM method on Windows systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103011. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart