Description
Heap-based buffer overflow in the legacy Blowfish encryption routine (BlowFishEncryptor::Encode, called by EncryptToString) in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows an authenticated mailbox user to cause a denial of service (service crash), and possibly other unspecified impact. In 6.3.4 and 6.3.5, where the self-service REST API is enabled (it is off by default), the user does this remotely by adding a fetch account whose password is 129 to 247 characters long and not a multiple of 8, and then requesting their personal data export (GET /api/v1/me/export.zip), which encrypts that password with the legacy scheme. The same flaw is reachable on Windows by any local interactive user with no hMailServer credentials, through the COM method Utilities.BlowfishEncrypt, which checked no authentication. It is also reachable by every stored-secret write when ProtectStoredSecretsWithDPAPI is set to 0. For such a length, the routine's padding loop writes up to 7 zero bytes 2 to 232 bytes past the end of its 255-byte heap buffer. The ciphertext it returns is still correct.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

A heap-based buffer overflow occurs in hMailServer's legacy Blowfish encryption routine (BlowFishEncryptor::Encode) when handling passwords of certain lengths. The flaw allows an attacker with a mailbox account to trigger a service crash, leading to denial of service, and may enable further undisclosed exploits. The same overflow can be triggered by locally logged‑on users via a COM interface that performs Blowfish encryption without authentication, or by users writing stored secrets when ProtectStoredSecretsWithDPAPI is disabled.

Affected Systems

The vulnerability affects Progressive Robot Ltd's hMailServer version 6.0.0 through 6.3.5, inclusive. Versions 6.3.4 and 6.3.5 are particularly vulnerable when the self‑service REST API is enabled, as an authenticated user can execute the overflow remotely during the personal‑data export operation. Any local interactive user with access to the server can also exploit the issue via the Utilities.BlowfishEncrypt COM method if the application is not properly locked down.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires user authentication to the hMailServer mailbox or local interactive access to the server, and the attacker must configure password lengths between 129 and 247 characters that are not multiples of eight when the REST API is enabled. Once triggered, the overflow writes up to seven bytes beyond the 255‑byte buffer, causing the application to crash. The attacker can exploit the flaw remotely through the REST API or locally through the COM method, making it a credible threat to availability for affected installations.

Generated by OpenCVE AI on October 8, 2026 at 12:50 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6. Until then: keep the REST API off (RestApiPort 0, the default) or open it only to trusted users; keep ProtectStoredSecretsWithDPAPI on (the default); do not grant remote DCOM activation to the hMailServer AppID; and do not give untrusted people an interactive logon on the server.


OpenCVE Recommended Actions

  • Upgrade hMailServer to version 6.3.6 or later.
  • Disable the REST API by setting RestApiPort to 0 or restrict it to trusted users only.
  • Ensure ProtectStoredSecretsWithDPAPI is set to 1 (enabled).
  • Revoke remote DCOM activation rights for the hMailServer AppID.
  • Remove interactive logon permissions for untrusted users on the server.

Generated by OpenCVE AI on October 8, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Progressive Robot
Progressive Robot hmailserver
Vendors & Products Progressive Robot
Progressive Robot hmailserver

Thu, 08 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in the legacy Blowfish encryption routine (BlowFishEncryptor::Encode, called by EncryptToString) in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows an authenticated mailbox user to cause a denial of service (service crash), and possibly other unspecified impact. In 6.3.4 and 6.3.5, where the self-service REST API is enabled (it is off by default), the user does this remotely by adding a fetch account whose password is 129 to 247 characters long and not a multiple of 8, and then requesting their personal data export (GET /api/v1/me/export.zip), which encrypts that password with the legacy scheme. The same flaw is reachable on Windows by any local interactive user with no hMailServer credentials, through the COM method Utilities.BlowfishEncrypt, which checked no authentication. It is also reachable by every stored-secret write when ProtectStoredSecretsWithDPAPI is set to 0. For such a length, the routine's padding loop writes up to 7 zero bytes 2 to 232 bytes past the end of its 255-byte heap buffer. The ciphertext it returns is still correct.
Title Heap-based Buffer Overflow in hMailServer
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Progressive Robot Hmailserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T14:22:03.806Z

Reserved: 2026-09-29T21:04:50.170Z

Link: CVE-2026-103011

cve-icon Vulnrichment

Updated: 2026-10-08T14:22:00.524Z

cve-icon NVD

Status : Received

Published: 2026-10-08T11:16:42.270

Modified: 2026-10-08T15:17:31.353

Link: CVE-2026-103011

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T13:00:07Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow