CVE-2026-107583
Received Received - Intake

Denial of Service in hMailServer Webmail

Vulnerability report for CVE-2026-107583, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. The route that renders a received message's HTML replaced each reference to an embedded image in place, with work that grew with the square of the number of references, and wrote the image out for every reference while counting it against its size limit only once. A message whose HTML refers to one small embedded image a very large number of times, opened in the webmail by its recipient, therefore keeps one of the listener's four worker threads busy for minutes and makes it build a document of gigabytes, so that a few such messages leave the HTTP listener unable to answer anybody.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.3.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107583 is a denial-of-service vulnerability in hMailServer's webmail message view feature. When a message's HTML contains an inline image referenced many times, the REST API route rendering the message inefficiently processes these references. The string replacement operation scales with the square of the number of references, causing excessive CPU and memory usage. This can build gigantic documents and exhaust server resources.

Detection Guidance

Monitor for unusually high CPU or memory usage on the hMailServer service, particularly when users access webmail. Check for excessive HTTP requests to the REST API endpoint GET /api/v1/me/messages/{id}/html. Look for messages with large numbers of embedded image references in their HTML content.

Impact Analysis

This vulnerability can make the webmail, administration console, and REST API unavailable. Attackers can send specially crafted messages that keep server threads busy for minutes, consuming excessive resources. Multiple such messages can crash the HTTP listener, preventing legitimate users from accessing their emails or managing the server.

Compliance Impact

This vulnerability primarily causes denial-of-service conditions by exhausting server resources, which could lead to service unavailability. While it does not directly expose or leak data, prolonged downtime may impact compliance with regulations requiring timely access to systems or data, such as GDPR's right to access or HIPAA's availability requirements.

Mitigation Strategies

Upgrade to hMailServer version 6.3.6 or later. If upgrading is not immediately possible, disable the REST listener, reduce the maximum message size, or disable the webmail offline store. Restart the hMailServer service after applying changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107583. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart