CVE-2026-107577
Received Received - Intake

MIME Processing Loop and Algorithmic Complexity in hMailServer

Vulnerability report for CVE-2026-107577, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Inefficient algorithmic complexity and a non-terminating loop in the MIME processing of received messages in Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote unauthenticated attacker to make the mail services unavailable by sending a message. Removing a MIME header parameter whose value is empty and directly followed by a semicolon (for example a Content-Disposition with 'filename=a.bat; filename=;') entered a loop that never terminates, holding a worker thread at full load until the server is restarted; this is reached when the attachment blocker renames a blocked attachment or a filename is set over the REST API. Separately, decoding a header field that holds many RFC 2047 encoded words of an encoding other than base64 or quoted-printable, removing a parameter with many RFC 2231 continuations, and deleting many header fields of one name each took time growing with the square of the message, on the small thread pools that serve IMAP, SMTP and POP3 connections, delivery and the REST API.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves three performance and denial-of-service issues in MIME message processing in hMailServer versions 6.0.0 to 6.3.5. The first is an infinite loop triggered when removing an empty MIME header parameter followed by a semicolon, causing a worker thread to hang indefinitely. The other two issues involve quadratic time complexity in decoding certain encoded headers and removing large numbers of header fields, which can exhaust thread pools and prevent message delivery until the server is restarted.

Detection Guidance

Monitor for hMailServer service hangs or crashes during MIME message processing. Check for high CPU usage by hMailServer threads. Review logs for messages with unusual MIME headers containing empty parameters followed by semicolons or excessive RFC 2047 encoded words.

Impact Analysis

An attacker can exploit these flaws to make mail services unavailable by sending a specially crafted message. This causes worker threads to hang or consume excessive resources, leading to service disruptions. The impact includes degraded performance, inability to deliver or process emails, and potential downtime until the server is manually restarted.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by causing service unavailability due to denial-of-service conditions. GDPR requires data controllers to ensure availability of personal data processing systems, while HIPAA mandates reliable access to protected health information. The infinite loop and resource exhaustion could lead to prolonged downtime, potentially violating availability requirements in these regulations.

Mitigation Strategies

Upgrade to hMailServer version 6.3.6 or later. Temporarily lower message size limits, disable attachment blocking, or restrict access to the REST API until patching. Monitor thread pool exhaustion and service availability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107577. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart