CVE-2026-107584
Received Received - Intake

DANE Bypass in hMailServer via DNSSEC Validation Failure

Vulnerability report for CVE-2026-107584, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Progressive Robot hMailServer 6.0.0 through 6.3.5 fails open when applying DANE (RFC 7672) to outbound SMTP delivery. The server's validating DNSSEC resolver treated a TLSA or MX lookup that did not complete (no answer, SERVFAIL, a malformed reply), an answer without the requested records and without an NSEC/NSEC3 proof of their absence, and an answer whose records carried no applicable RRSIG as if the recipient domain were unsigned, and from 6.2.19 it also delivered to mail exchangers taken from an unvalidated MX lookup that the DNSSEC-validated MX record set did not name. An attacker who can drop, forge or strip DNS answers on the path to the server's resolver, at the resolver, or between the resolver and the recipient domain's name servers, and who holds an active position on the SMTP path, can thereby disable DANE for a DNSSEC-signed recipient domain and cause messages to be delivered in cleartext or to a host of the attacker's choosing with an arbitrary certificate, where they can be read and modified.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-636 When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

hMailServer versions 6.0.0 through 6.3.5 have a flaw in their DANE (DNS-based Authentication of Named Entities) handling for outbound SMTP delivery. The server's DNSSEC-validating resolver incorrectly treats incomplete or unsigned DANE lookups as if the recipient domain were unsigned. This allows an attacker on the network path to manipulate DNS responses, disable DANE security for DNSSEC-signed domains, and force email delivery in cleartext or to malicious hosts with arbitrary certificates.

Detection Guidance

To detect this vulnerability, monitor hMailServer logs for failed DANE or DNSSEC validation events during outbound SMTP delivery. Check if emails to DNSSEC-signed domains are delivered in cleartext or to unexpected hosts. Use network tools like tcpdump or Wireshark to inspect SMTP traffic for unencrypted connections to domains that should enforce DANE.

Impact Analysis

This vulnerability allows attackers to intercept, read, or modify emails sent through hMailServer. Emails may be delivered in plaintext instead of encrypted, exposing sensitive information. Attackers could also redirect emails to servers under their control by presenting fake certificates, enabling further attacks like phishing or data theft.

Compliance Impact

This vulnerability can lead to non-compliance with GDPR and HIPAA due to the exposure of sensitive data in transit. GDPR requires protection of personal data, and HIPAA mandates encryption for protected health information. Failure to secure email communications could result in violations, legal penalties, and loss of trust.

Mitigation Strategies

Upgrade hMailServer to version 6.3.6 or later to address the DANE handling flaw. If upgrading is not possible, disable DANE enforcement and enforce mandatory STARTTLS with remote certificate validation for all outbound SMTP connections. Ensure your DNS resolver is secure and validates DNSSEC records properly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107584. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart