CVE-2026-107572: CWE-1333: Inefficient Regular Expression Complexity in Progressive Robot Ltd hMailServer
Description
Inefficient complexity in the Sieve filter evaluation of Progressive Robot hMailServer 6.2.24 through 6.3.5 allows an authenticated account holder to make the mail services unavailable with their own filter. A ':matches' pattern was matched by a backtracking descent whose time grew with the matched value's length raised to the number of wildcards, so a pattern such as '*a*a*a*b' over 800 characters took 44 seconds; and 'deleteheader' erased the fields it removed one at a time, so removing many fields of one name over a message's header cost O(N^2) (80,000 fields took 18.8 seconds). Sieve filters run on the small, shared delivery thread pool, so an account holder whose active script does this, fed a few messages they can send themselves, empties the pool and stops delivery for the whole server. The script is the account holder's own and cannot be set for another user.
CVSS v3.1
Score 6.5medium
Affected software
Progressive Robot Ltd
hMailServer
pkg:github/hmailserver/hmailserverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in hMailServer versions >=6.2.24 and <6.3.6 is caused by inefficient complexity in the Sieve filter evaluation. Specifically, the ':matches' pattern uses a backtracking descent whose time complexity grows exponentially with the number of wildcards and the length of the matched string. For example, a pattern like '*a*a*a*b' over 800 characters took 44 seconds to process. Additionally, the 'deleteheader' command removes fields one at a time, resulting in quadratic time complexity when removing many fields. Since Sieve filters run on a small, shared delivery thread pool, an authenticated user can craft a filter that consumes all threads by feeding messages to their own script, causing a denial of service for the entire mail server. The script can only affect the account holder's own filters, not those of other users.
Potential Impact
An authenticated user can cause a denial of service by creating a Sieve filter that consumes excessive CPU time and thread pool resources, effectively stopping mail delivery for all users on the server. There is no impact on confidentiality or integrity, only availability is affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should monitor for unusually resource-intensive Sieve filters and consider restricting or auditing user-created filters to prevent denial of service. Since the vulnerability requires authenticated access and affects only the user's own filters, limiting account privileges and monitoring filter usage can help mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitLab
- Date Reserved
- 2026-10-08T10:51:25.637Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac786ba2cdf04f65611bbb6
Added to database: 10/08/2026, 12:04:10 UTC
Last enriched: 10/08/2026, 12:19:29 UTC
Last updated: 10/08/2026, 18:06:37 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.