CVE-2026-107579
Received Received - Intake

Algorithmic Complexity DoS in hMailServer

Vulnerability report for CVE-2026-107579, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Inefficient algorithmic complexity in the bounce and complaint processing of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to stop mail delivery by sending messages, when bounce processing or complaint processing is enabled or a mailing list is managed by the server (none is by default). The readers of incoming delivery status notifications (RFC 3464) and abuse feedback reports (RFC 5965) removed the blank lines at the start of the returned headers part two bytes at a time, copying the rest of the part each time, so their work grew with the square of the number of blank lines. A message shaped like such a report, whose headers part begins with a very large number of blank lines within the reader's 2 MB limit, keeps a delivery thread busy for over a minute while it is delivered, and a few such messages a minute keep every delivery thread busy.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.3.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107579 is a denial-of-service (DoS) vulnerability in hMailServer versions 6.3.4 and 6.3.5 affecting bounce, complaint, and mailing-list bounce processing. Attackers exploit it by sending messages with a large number of leading blank lines in the headers section of delivery status notifications or abuse feedback reports. The parsers inefficiently remove these blank lines two bytes at a time, causing processing time to grow quadratically with the number of blank lines. This consumes excessive CPU resources and delays or halts mail delivery.

Detection Guidance

Monitor for unusually high CPU usage or delayed message delivery on hMailServer 6.3.4 or 6.3.5. Check logs for messages with excessive blank lines in headers. Use network monitoring tools to detect abnormal traffic patterns targeting mail services.

Impact Analysis

This vulnerability can cause severe disruptions to email services. An attacker could send specially crafted messages that keep all delivery threads busy for over a minute per message. Multiple such messages could overload the server, preventing it from processing legitimate emails. This leads to delayed or failed email delivery for all users relying on the affected hMailServer instance.

Compliance Impact

This vulnerability primarily causes denial-of-service by consuming excessive server resources, which could disrupt email services. For compliance with GDPR or HIPAA, such disruptions may impact data processing timelines or availability of critical communications, potentially violating requirements for timely data handling or secure communication channels.

Mitigation Strategies
  • Disable bounce processing, complaint processing, and mailing-list management in hMailServer settings.
  • Upgrade hMailServer to version 6.3.6 or later to apply the fix.
  • Reduce the maximum message size limit to limit the impact of malformed messages.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107579. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart