CVE-2026-107575
Received Received - Intake

Algorithmic Complexity DoS in hMailServer SPF Macro Expansion

Vulnerability report for CVE-2026-107575, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Inefficient algorithmic complexity in the SPF macro expansion of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to consume worker-thread time by publishing a crafted SPF record. RFC 7208 section 7.1 requires a name too long to look up to lose whole labels from the left; the server did this by removing one label at a time and copying the rest of the name each time, so the work grew with the square of the expansion. An attacker who publishes an SPF record for a domain they control, with a mechanism whose domain-spec expands through macros to a name far longer than 253 characters, makes the SPF check of a message from that domain take several seconds. The expansion is bounded by SPF's own per-term and per-macro limits, so the loss of availability is partial.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.3.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in hMailServer versions 6.3.4 and 6.3.5. It involves inefficient SPF macro expansion where processing a long domain-spec (over 253 characters) causes quadratic time complexity. The server removes one label at a time in a loop, copying the remaining string each iteration, making processing time grow with the square of the expansion length. This can delay SPF checks by several seconds per message.

Detection Guidance

Monitor hMailServer logs for SPF processing delays or timeouts during email delivery. Check for messages from domains with unusually long SPF records (over 253 characters). Use network monitoring tools to detect CPU spikes during SPF checks.

Impact Analysis

An attacker can exploit this by publishing a crafted SPF record for a domain they control. When hMailServer processes emails from that domain, it may consume excessive CPU resources, causing delays of up to several seconds per message. This can degrade server performance and disrupt email delivery.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar standards as it primarily causes performance degradation rather than data breaches or unauthorized access. However, prolonged delays in email processing could indirectly affect compliance by disrupting communication workflows or delaying critical notifications.

Mitigation Strategies
  • Disable SPF and DMARC anti-spam tests in hMailServer settings.
  • Turn off ARC test and greylisting's SPF bypass if enabled.
  • Upgrade hMailServer to version 6.3.6 or later to apply the fix.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107575. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart