CVE-2026-107585
Received Received - Intake

Uncontrolled Eviction in hMailServer REST API

Vulnerability report for CVE-2026-107585, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitLab Inc.

Description

Uncontrolled eviction in the pending sign-in tables of the REST API in Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to make other users' OpenID Connect, SAML and passkey sign-ins fail. The routes that start a single sign-on and hand out a passkey sign-in challenge are reached without authentication and stored pending state in bounded tables that dropped their oldest entry when full, whoever had started it. An attacker who starts sign-ins a few times a second (about a hundred a second for passkeys) pushes every other user's pending sign-in out of the table before that user's browser returns, denying single sign-on and passkey sign-in for as long as the requests continue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progressive Robot Ltd hMailServer 6.3.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to disrupt single sign-on (SSO), OpenID Connect, SAML, and passkey sign-ins by flooding the server's pending sign-in tables. The attacker sends frequent requests to start sign-ins, filling the bounded tables and pushing out legitimate users' pending sign-ins before they can complete authentication.

Detection Guidance

Monitor for unusual traffic patterns targeting the REST API routes /portal/oidc/start, /portal/saml/start, or /api/v1/passkeys/challenge. Check for repeated requests from the same IP address exceeding normal user behavior. Inspect server logs for failed SSO or passkey sign-in attempts during sign-on processes.

Impact Analysis

If you rely on SSO, OpenID Connect, SAML, or passkey sign-ins for hMailServer, this vulnerability could prevent you from logging in during an attack. Password sign-ins and existing sessions remain unaffected. Attackers can deny access to these authentication methods by sending about 100 requests per second.

Compliance Impact

This vulnerability does not directly impact GDPR or HIPAA compliance as it primarily causes a denial-of-service for single sign-on and passkey sign-ins without exposing or altering user data. However, prolonged denial-of-service could disrupt access to systems handling personal or health data, potentially violating availability requirements under GDPR Article 32 or HIPAA Security Rule.

Mitigation Strategies

Upgrade to hMailServer version 6.3.6 or later to apply the fix. If upgrading is not immediately possible, implement rate-limiting on the vulnerable routes at a reverse proxy level. Temporarily disable SSO and passkey features or switch to password-based sign-ins for critical accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107585. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart