Skip to main content

CVE-2026-107574: CWE-407: Inefficient Algorithmic Complexity in Progressive Robot Ltd hMailServer

0
High
VulnerabilityCVE-2026-107574cvecve-2026-107574cwe-407
Published: 10/08/2026 (10/08/2026, 11:46:26 UTC)
Source: CVE Database V5
Vendor/Project: Progressive Robot Ltd
Product: hMailServer

Description

Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the mail services unavailable. Reading a JSON object kept the first of each duplicated member name by searching the members already read, so an object of N distinct member names cost O(N^2): 1 MB took 8.9 seconds and 4 MB took 300 seconds against the affected code. A remote attacker reaches the reader without an account by mailing a crafted TLS-RPT report (up to 16 MB after decompression) to a hosted domain's published report mailbox, which is read on a delivery thread; a few such reports hold every delivery thread (ten by default), so the server delivers no mail, local or outbound, for over an hour per report. A signed-in account reaches the same 16 MB body through the webmail's own REST routes, holding the REST API's own worker threads. Where no report mailbox is configured, the unauthenticated REST sign-in routes that read a JSON body are capped at 64 KB and are not affected.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

Progressive Robot Ltd

hMailServer

Affected versions
>=6.2.28 <6.3.6
GitHub Actionsmore threats →ai
hmailserver/hmailserver
pkg:github/hmailserver/hmailserver
Affected versions
>=6.2.28 <6.3.6

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 12:03:25 UTC

Technical Analysis

The vulnerability in hMailServer's JSON reader causes inefficient processing due to an O(N^2) algorithm when handling duplicated JSON member names. This inefficiency can be exploited by remote unauthenticated attackers sending large crafted TLS-RPT reports (up to 16 MB after decompression) to a hosted domain's report mailbox, which is processed on delivery threads. This leads to thread exhaustion and denial of service, preventing mail delivery for over an hour per report. Signed-in users can similarly exhaust REST API worker threads by sending large JSON bodies via webmail REST routes. Systems without a report mailbox configured and with REST routes limited to 64 KB JSON bodies are not vulnerable to this attack vector.

Potential Impact

The vulnerability results in denial of service (DoS) by exhausting mail delivery and REST API worker threads, making mail services unavailable locally and outbound for extended periods. There is no impact on confidentiality or integrity. The attack requires no privileges or user interaction for the TLS-RPT report vector, making it remotely exploitable without authentication. The REST API vector requires a signed-in account but can similarly cause resource exhaustion.

Mitigation Recommendations

No official patch information is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should consider disabling or restricting the TLS-RPT report mailbox or limiting the size of incoming JSON payloads if possible. Systems without a configured report mailbox and with REST sign-in routes capped at 64 KB are not affected by this vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitLab
Date Reserved
2026-10-08T10:51:35.642Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac7833d2cdf04f65610accf

Added to database: 10/08/2026, 11:49:17 UTC

Last enriched: 10/08/2026, 12:03:25 UTC

Last updated: 10/08/2026, 15:04:12 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses