Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade to hMailServer 6.3.6, which unfolds a header value in one pass and searches a header being read only in what each read adds. Until then: lower the maximum message size, which bounds the cost (it grows with the square of the value's size); remove such a message over POP3; or keep the REST listener off (RestApiPort 0, the default).
Workaround
No workaround given by the vendor.
Thu, 08 Oct 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Inefficient algorithmic complexity in the decoding of message header fields in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the IMAP, SMTP and POP3 services, or the webmail, unavailable by sending a message. The server unfolded a decoded header value by finding each line break from the end of the value and removing it, moving the rest of the value each time, so its work grew with the square of the number of line breaks, and an RFC 2047 encoded word may decode to any number of them. A received message whose Subject or other header field holds such a value keeps a worker thread busy for minutes or longer each time the value is read: when the recipient's IMAP client searches, sorts or threads the folder by a header, when the webmail lists the folder, and, where configured, when a rule tests a header, a spam tag is added to the Subject or an abuse report is read during delivery. The IMAP worker threads are shared with SMTP and POP3, so a few such messages stop those services responding. The server's reading of a message header from its file also searched everything read so far after each 4,000 bytes, costing seconds for a header of tens of megabytes. | |
| Title | Inefficient Algorithmic Complexity in hMailServer | |
| Weaknesses | CWE-407 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-10-08T11:47:11.085Z
Reserved: 2026-10-08T10:52:05.641Z
Link: CVE-2026-107580
No data.
Status : Received
Published: 2026-10-08T12:17:16.123
Modified: 2026-10-08T12:17:16.123
Link: CVE-2026-107580
No data.
OpenCVE Enrichment
No data.