CVE-2026-107576
Received Received - Intake

Denial of Service in hMailServer via DKIM Verification

Vulnerability report for CVE-2026-107576, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the mail services unavailable by sending a message. Building the canonical header and choosing the header fields named in a signature's h= tag took time growing with the square of the message's header: the 'simple' canonicalisation prepended each continuation line of a folded field to the lines already gathered, and both canonicalisations searched the gathered fields from the bottom for each h= name and erased the match from the middle of the list. A message whose header holds very many fields, or a field folded over very many lines, with a DKIM-Signature the attacker signs for a domain they control, keeps a worker thread busy for tens of seconds per signature; up to ten signatures are evaluated per message by each of the DKIM and DMARC tests, on the threads that serve delivery and SMTP.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in hMailServer 6.0.0 through 6.3.5 involves inefficient algorithmic complexity during DKIM and ARC signature verification for incoming messages. The issue causes processing time to grow quadratically with the size of the message's header due to poor methods in building canonical headers and selecting signed fields. This can lead to significant delays, up to tens of seconds per signature, potentially making mail services unavailable.

Detection Guidance

Detecting this vulnerability requires checking hMailServer versions 6.0.0 through 6.3.5 and monitoring for unusually slow DKIM or ARC signature verification. Check server logs for delayed message processing during DKIM verification. No specific commands are provided in the context, but monitoring CPU and memory usage during email processing may indicate the issue.

Impact Analysis

This vulnerability can impact you by causing your mail server to become unresponsive or unavailable. Attackers can exploit it by sending specially crafted messages with large headers or folded fields, consuming server resources and preventing legitimate email delivery. The default DKIM verification multiplies the impact as each message may be checked against up to ten signatures.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA. However, the denial-of-service risk from excessive resource consumption could impact availability requirements in these standards. GDPR requires data processing systems to ensure availability, while HIPAA mandates safeguards against disruptions. Unpatched servers may fail to meet these availability expectations.

Mitigation Strategies

Upgrade hMailServer to version 6.3.6 or later to fix the inefficiency. If upgrading is not immediately possible, reduce the maximum message size to limit header complexity. Disable DKIM or DMARC verification temporarily if the server is under attack, but note this does not resolve the underlying issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107576. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart