CVE-2026-107580
Received Received - Intake

Denial of Service in hMailServer via Header Decoding

Vulnerability report for CVE-2026-107580, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Inefficient algorithmic complexity in the decoding of message header fields in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the IMAP, SMTP and POP3 services, or the webmail, unavailable by sending a message. The server unfolded a decoded header value by finding each line break from the end of the value and removing it, moving the rest of the value each time, so its work grew with the square of the number of line breaks, and an RFC 2047 encoded word may decode to any number of them. A received message whose Subject or other header field holds such a value keeps a worker thread busy for minutes or longer each time the value is read: when the recipient's IMAP client searches, sorts or threads the folder by a header, when the webmail lists the folder, and, where configured, when a rule tests a header, a spam tag is added to the Subject or an abuse report is read during delivery. The IMAP worker threads are shared with SMTP and POP3, so a few such messages stop those services responding. The server's reading of a message header from its file also searched everything read so far after each 4,000 bytes, costing seconds for a header of tens of megabytes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service issue in hMailServer versions 6.0.0 through 6.3.5 caused by inefficient header unfolding logic. When processing email headers with many line breaks or large values, the server's algorithm takes quadratic time to decode them, causing worker threads to hang for minutes or longer. Attackers can exploit this by sending specially crafted emails to make IMAP, SMTP, POP3, and webmail services unavailable.

Detection Guidance

Monitor for unusually high CPU or memory usage on hMailServer services (IMAP, SMTP, POP3) during email processing. Check for slow or unresponsive IMAP commands like SEARCH, SORT, or THREAD. Inspect logs for messages with excessively large or malformed headers.

Impact Analysis

If exploited, this vulnerability can make your email server unresponsive or crash, disrupting email services for all users. IMAP clients may freeze when searching or sorting emails, and SMTP/POP3 services could stop responding entirely. Webmail interfaces may also become slow or unusable. The attack requires no authentication and can be triggered by a single malicious email.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by causing prolonged service outages, potentially violating availability requirements. If email services are disrupted, organizations may fail to meet regulatory obligations for timely communication and data access. The lack of authentication for exploitation increases risk exposure.

Mitigation Strategies

Upgrade to hMailServer version 6.3.6 or later. Disable DMARC checks if enabled. Reduce maximum message size limits. Turn off anti-spam scan size limits. Disable the REST listener if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107580. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart