CVE-2026-103649
Received Received - Intake

Missing Network Timeouts in hMailServer Cause Denial of Service

Vulnerability report for CVE-2026-103649, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Missing network timeouts in the Linux builds of Progressive Robot hMailServer 6.3.0 through 6.3.5 allow a remote attacker to hold server threads indefinitely and so stop outbound mail delivery (denial of service). The server set its socket timeouts in the form Windows takes, which Linux refuses, and its HTTPS clients read without a deadline, so a peer that accepts a connection and then sends nothing held the waiting thread for as long as the connection stayed open. The MTA-STS policy fetch, enabled by default, is made during outbound delivery to mta-sts.<recipient domain>, so anyone who can make the server deliver mail to a domain they control - for example as the envelope sender of a message that bounces - can hold delivery threads until outbound delivery stops. The same flaw affects the DANE TLSA query, the OAuth2 token request, the ACME client, and the ManageSieve and metrics listeners, which a silent client stops from serving anyone else. Windows builds are not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1088 The code has a synchronous call to a remote resource, but there is no timeout for the call, or the timeout is set to infinite.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves missing network timeouts in hMailServer 6.3.0 through 6.3.5 on Linux. Remote attackers can exploit this by holding server threads indefinitely, stopping outbound mail delivery and making services unresponsive. The issue occurs because Linux ignores Windows-style timeout formats and lacks deadlines for blocking calls.

Detection Guidance

Check for hung threads in hMailServer by monitoring process activity and network connections. Use 'ps aux | grep hmailserver' to verify the process is running and 'netstat -tulnp | grep hmailserver' to inspect active connections. Look for processes stuck in 'D' state (uninterruptible sleep) which may indicate hung threads.

Impact Analysis

It can cause denial-of-service by halting mail delivery or freezing services like ManageSieve and metrics listeners. Attackers can exploit this by sending maliciously crafted requests that never complete, tying up server resources until outbound delivery stops entirely.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by causing prolonged service disruptions due to denial-of-service conditions. Under GDPR, organizations must ensure the availability of personal data processing systems, and prolonged outages may violate this requirement. HIPAA mandates timely access to protected health information, and stalled mail delivery could hinder compliance with notification and communication obligations.

Mitigation Strategies

Disable MTA-STS in hMailServer configuration to prevent policy fetch hangs. Restrict access to ManageSieve and metrics listeners by binding them to localhost or specific IPs. Restart the hMailServer service periodically to clear hung threads. Upgrade to version 6.3.6 or later once available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103649. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart