CVE-2026-107581
Received Received - Intake

IMAP Command Quadratic Processing in hMailServer

Vulnerability report for CVE-2026-107581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadratic in the command's length or in the number of elements it names, and can be made to hold memory out of proportion to a command. The FETCH data-item parser normalised a BODY[] section with a case-insensitive string replacement that copied the whole item per occurrence and split the item list by repeatedly copying the remainder of the command; the server's case-insensitive search compared a needle afresh at every position, so a long SEARCH TEXT key over a message cost the product of the two lengths; SEARCH message sets and the saved-result marker ($), SORT criteria, HEADER.FIELDS name lists and UID ranges were each read once per message rather than once per command; and a FETCH naming a message's sections very many times read and held every section in memory before sending any. An IMAP command may continue past one line through non-synchronizing literals, so one command can reach about eleven megabytes. The IMAP worker threads are a small pool shared with SMTP and POP3, so a signed-in user sending such commands can make the IMAP, SMTP and POP3 services stop responding (CWE-407) and can consume excessive memory (CWE-400).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107581 is a vulnerability in hMailServer's IMAP command handling. An authenticated user can send a specially crafted command that causes the server to process it inefficiently, taking quadratic time relative to the command's length or referenced elements. This leads to excessive CPU usage and memory consumption, potentially freezing IMAP, SMTP, and POP3 services.

Detection Guidance

Monitor IMAP service performance for unusual CPU or memory spikes during IMAP operations. Check for commands with excessive length or repeated elements in FETCH, SEARCH, SORT, or HEADER.FIELDS operations. Use system monitoring tools to detect unresponsive IMAP, SMTP, or POP3 services.

Impact Analysis

This vulnerability allows an attacker with access to an IMAP account to disrupt email services by consuming excessive server resources. It can cause services to become unresponsive, leading to downtime for all users. The attack may also consume significant memory, potentially crashing the server.

Compliance Impact

This vulnerability could lead to denial-of-service conditions affecting IMAP, SMTP, and POP3 services, potentially disrupting access to sensitive data. For GDPR, this may impact availability of personal data processing systems. For HIPAA, it could disrupt access to protected health information systems. Both standards require availability of critical systems handling sensitive data.

Mitigation Strategies

Upgrade hMailServer to version 6.3.6 or later to apply the official fix. Restrict IMAP access to trusted accounts and networks. Temporarily disable non-essential IMAP features if an upgrade is not immediately possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107581. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart