CVE-2026-107574
Received Received - Intake

Denial of Service in hMailServer via JSON Reader

Vulnerability report for CVE-2026-107574, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the mail services unavailable. Reading a JSON object kept the first of each duplicated member name by searching the members already read, so an object of N distinct member names cost O(N^2): 1 MB took 8.9 seconds and 4 MB took 300 seconds against the affected code. A remote attacker reaches the reader without an account by mailing a crafted TLS-RPT report (up to 16 MB after decompression) to a hosted domain's published report mailbox, which is read on a delivery thread; a few such reports hold every delivery thread (ten by default), so the server delivers no mail, local or outbound, for over an hour per report. A signed-in account reaches the same 16 MB body through the webmail's own REST routes, holding the REST API's own worker threads. Where no report mailbox is configured, the unauthenticated REST sign-in routes that read a JSON body are capped at 64 KB and are not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.2.28

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107574 is a denial-of-service vulnerability in hMailServer's JSON reader. It occurs because the reader inefficiently handles duplicated member names in JSON objects, causing quadratic time complexity (O(n^2)). This means parsing large JSON files takes exponentially longer than it should.

Detection Guidance

Monitor CPU usage spikes during JSON parsing tasks. Check mail server logs for unusually large TLS-RPT reports (16 MB) being processed. Inspect delivery thread exhaustion in hMailServer logs. Disable domain reports temporarily to test if mail delivery resumes.

Impact Analysis

An attacker can exploit this by sending a large 16 MB TLS-RPT report to a domain's mailbox without authentication. This consumes all delivery threads, halting all mail processing for over an hour per report. Even authenticated users can trigger it via webmail's REST routes, blocking API worker threads.

Compliance Impact

This vulnerability could lead to prolonged unavailability of mail services, potentially causing delays or failures in processing sensitive communications. For GDPR, this may impact the right to timely data processing and communication. For HIPAA, it could disrupt the transmission of protected health information, risking compliance with timely access requirements.

Mitigation Strategies

Upgrade hMailServer to version 6.3.6 or later. Disable domain reports or OpenPGP functionality until patched. Block large TLS-RPT reports at the mail gateway if possible. Monitor mail delivery threads for signs of resource exhaustion.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107574. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart