CVE-2026-107572
Received Received - Intake

Denial of Service in hMailServer via Sieve Filter

Vulnerability report for CVE-2026-107572, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Inefficient complexity in the Sieve filter evaluation of Progressive Robot hMailServer 6.2.24 through 6.3.5 allows an authenticated account holder to make the mail services unavailable with their own filter. A ':matches' pattern was matched by a backtracking descent whose time grew with the matched value's length raised to the number of wildcards, so a pattern such as '*a*a*a*b' over 800 characters took 44 seconds; and 'deleteheader' erased the fields it removed one at a time, so removing many fields of one name over a message's header cost O(N^2) (80,000 fields took 18.8 seconds). Sieve filters run on the small, shared delivery thread pool, so an account holder whose active script does this, fed a few messages they can send themselves, empties the pool and stops delivery for the whole server. The script is the account holder's own and cannot be set for another user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.2.24

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1333 The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in hMailServer versions 6.2.22 to 6.3.5 allows an authenticated user to cause a denial of service by exploiting inefficient Sieve filter operations. The issue involves two problems: first, the ':matches' pattern matching uses exponential backtracking with wildcards, making processing time grow rapidly with input size. Second, the 'deleteheader' command removes fields one at a time, causing quadratic time complexity. Both operations run on a shared thread pool, and an attacker can exhaust it by sending a few messages, stopping email delivery for the entire server.

Detection Guidance

Review active Sieve scripts for patterns with multiple wildcards in `:matches` commands or excessive use of `deleteheader`. Monitor server performance for unusual delays in email delivery or thread pool exhaustion. Check hMailServer logs for scripts causing high CPU or memory usage during filter processing.

Impact Analysis

If you use hMailServer versions 6.2.22 to 6.3.5, an attacker with access to set their own Sieve script could make your mail server unavailable. This means emails may not be delivered to any users on the server, disrupting communication. The attack requires only a few messages sent by the attacker to themselves.

Compliance Impact

This vulnerability primarily causes denial of service by exhausting server resources through inefficient Sieve filter operations. It does not directly expose or leak data, so it may not directly violate GDPR or HIPAA data protection requirements. However, prolonged unavailability of email services could disrupt compliance-related communications, potentially leading to violations of time-sensitive regulatory obligations under these standards.

Mitigation Strategies

Upgrade to hMailServer version 6.3.6 or later to apply the fixes for the `:matches` and `deleteheader` issues. Temporarily disable Sieve filters for affected accounts or review scripts for malicious patterns. Limit the maximum message size to reduce potential impact from large inputs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107572. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart