CVE-2026-107582
Received Received - Intake

Denial of Service in hMailServer REST API and IMAP

Vulnerability report for CVE-2026-107582, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Inefficient algorithmic complexity in the REST API (6.3.3 through 6.3.5) and the IMAP PREVIEW response (6.2.22 through 6.3.5) of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. To show a snippet of each message in a folder's message list, the server decoded the character entity references of a message that has an HTML part and no text part with a string replacement whose work grew with the square of their number. A received HTML-only message holding a very large number of entity references therefore keeps one of the listener's four worker threads busy for minutes or longer each time the recipient's webmail lists the folder, without the message being opened, so that a few such listings leave the HTTP listener unable to answer anybody. The IMAP PREVIEW response read such text the same way, holding an IMAP thread for each client that asks for the preview of such a message. The flaw is in the server's shared string class, whose replace and remove both ran in quadratic time.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.2.22-pre1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service flaw in hMailServer caused by inefficient string replacement and removal operations that run in quadratic time. When processing HTML-only messages with many character entity references or spaces, the server's performance degrades significantly. A malicious sender can exploit this by sending a large message to make the webmail, administration console, and REST API unavailable.

Detection Guidance

Monitor for unusually high CPU or memory usage on the hMailServer process, especially when users access folder listings or IMAP previews. Check for messages with excessive character entities or spaces in HTML parts, particularly in DKIM signatures. Use server logs to identify delays in REST API, webmail, or IMAP responses.

Impact Analysis

The vulnerability can cause your hMailServer to become unresponsive or crash. Attackers can send specially crafted messages to consume server resources, making email services, webmail, and administration tools unavailable. Even listing folders or checking IMAP previews can trigger delays or crashes.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA. However, the denial-of-service impact on hMailServer's availability could indirectly affect compliance by disrupting email-based communications required for data processing or notifications under these regulations.

Mitigation Strategies

Upgrade hMailServer to version 6.3.6 or later to fix the quadratic time complexity issue. If upgrading is not immediately possible, reduce the maximum message size, delete messages with large numbers of entities, restart the hMailServer service, disable the REST listener, or turn off DMARC and DKIM anti-spam tests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107582. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart