CVE-2026-107574: CWE-407: Inefficient Algorithmic Complexity in Progressive Robot Ltd hMailServer
Description
Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the mail services unavailable. Reading a JSON object kept the first of each duplicated member name by searching the members already read, so an object of N distinct member names cost O(N^2): 1 MB took 8.9 seconds and 4 MB took 300 seconds against the affected code. A remote attacker reaches the reader without an account by mailing a crafted TLS-RPT report (up to 16 MB after decompression) to a hosted domain's published report mailbox, which is read on a delivery thread; a few such reports hold every delivery thread (ten by default), so the server delivers no mail, local or outbound, for over an hour per report. A signed-in account reaches the same 16 MB body through the webmail's own REST routes, holding the REST API's own worker threads. Where no report mailbox is configured, the unauthenticated REST sign-in routes that read a JSON body are capped at 64 KB and are not affected.
CVSS v3.1
Score 7.5high
Affected software
Progressive Robot Ltd
hMailServer
pkg:github/hmailserver/hmailserverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in hMailServer's JSON reader causes inefficient processing due to an O(N^2) algorithm when handling duplicated JSON member names. This inefficiency can be exploited by remote unauthenticated attackers sending large crafted TLS-RPT reports (up to 16 MB after decompression) to a hosted domain's report mailbox, which is processed on delivery threads. This leads to thread exhaustion and denial of service, preventing mail delivery for over an hour per report. Signed-in users can similarly exhaust REST API worker threads by sending large JSON bodies via webmail REST routes. Systems without a report mailbox configured and with REST routes limited to 64 KB JSON bodies are not vulnerable to this attack vector.
Potential Impact
The vulnerability results in denial of service (DoS) by exhausting mail delivery and REST API worker threads, making mail services unavailable locally and outbound for extended periods. There is no impact on confidentiality or integrity. The attack requires no privileges or user interaction for the TLS-RPT report vector, making it remotely exploitable without authentication. The REST API vector requires a signed-in account but can similarly cause resource exhaustion.
Mitigation Recommendations
No official patch information is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should consider disabling or restricting the TLS-RPT report mailbox or limiting the size of incoming JSON payloads if possible. Systems without a configured report mailbox and with REST sign-in routes capped at 64 KB are not affected by this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitLab
- Date Reserved
- 2026-10-08T10:51:35.642Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac7833d2cdf04f65610accf
Added to database: 10/08/2026, 11:49:17 UTC
Last enriched: 10/08/2026, 12:03:25 UTC
Last updated: 10/08/2026, 15:04:12 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.