Description
Missing network timeouts in the Linux builds of Progressive Robot hMailServer 6.3.0 through 6.3.5 allow a remote attacker to hold server threads indefinitely and so stop outbound mail delivery (denial of service). The server set its socket timeouts in the form Windows takes, which Linux refuses, and its HTTPS clients read without a deadline, so a peer that accepts a connection and then sends nothing held the waiting thread for as long as the connection stayed open. The MTA-STS policy fetch, enabled by default, is made during outbound delivery to mta-sts.<recipient domain>, so anyone who can make the server deliver mail to a domain they control - for example as the envelope sender of a message that bounces - can hold delivery threads until outbound delivery stops. The same flaw affects the DANE TLSA query, the OAuth2 token request, the ACME client, and the ManageSieve and metrics listeners, which a silent client stops from serving anyone else. Windows builds are not affected.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Missing network timeouts in the Linux builds cause server threads to hang indefinitely when a remote peer accepts a connection and then sends no data. The result is a denial of service that blocks outbound mail delivery, as the server cannot finish processing the request. This flaw also applies to several components that perform network requests, such as MTA‑STS policy fetching, DANE TLSA queries, OAuth2 token requests, ACME client operations, and the ManageSieve and metrics listeners.

Affected Systems

The vulnerability affects Progressive Robot Ltd’s hMailServer versions 6.3.0 through 6.3.5 running on Linux; Windows builds are not impacted. The flaw manifests in components that perform synchronous remote calls, including the embedded HTTP client used for policy and credential retrieval and the listeners that respond to client connections.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity denial of service. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a remote attacker who can interact with the hMailServer instance over the network and in some cases control the recipient domain of the outbound message. Based on the description, the likely attack vector is remote network access to the Linux host running hMailServer. The risk is moderate to high due to the impact on mail delivery and potential cascading denial of service for users.

Generated by OpenCVE AI on October 8, 2026 at 12:22 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, where every one of these requests and listeners has a deadline on Linux as on Windows. Until then, on Linux: set MtaStsEnabled to 0 if outbound delivery stalls, keep ManageSieve and the metrics listener off or reachable only from trusted networks, and restart the service to release held threads.


OpenCVE Recommended Actions

  • Upgrade hMailServer to version 6.3.6 or later, where all network calls enforce deadlines on Linux as well as on Windows.
  • On Linux, set MtaStsEnabled to 0 to prevent outbound delivery from fetching MTA‑STS policies that could trigger the hang.
  • Disable or restrict access to the ManageSieve and metrics listeners to trusted networks only, or turn them off entirely until a patch is applied.
  • Restart the hMailServer service to release any threads that may be stuck and clear the current backlog.

Generated by OpenCVE AI on October 8, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Progressive Robot
Progressive Robot hmailserver
Vendors & Products Progressive Robot
Progressive Robot hmailserver

Thu, 08 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Missing network timeouts in the Linux builds of Progressive Robot hMailServer 6.3.0 through 6.3.5 allow a remote attacker to hold server threads indefinitely and so stop outbound mail delivery (denial of service). The server set its socket timeouts in the form Windows takes, which Linux refuses, and its HTTPS clients read without a deadline, so a peer that accepts a connection and then sends nothing held the waiting thread for as long as the connection stayed open. The MTA-STS policy fetch, enabled by default, is made during outbound delivery to mta-sts.<recipient domain>, so anyone who can make the server deliver mail to a domain they control - for example as the envelope sender of a message that bounces - can hold delivery threads until outbound delivery stops. The same flaw affects the DANE TLSA query, the OAuth2 token request, the ACME client, and the ManageSieve and metrics listeners, which a silent client stops from serving anyone else. Windows builds are not affected.
Title Synchronous Access of Remote Resource without Timeout in hMailServer
Weaknesses CWE-1088
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Progressive Robot Hmailserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T14:24:21.363Z

Reserved: 2026-10-01T07:04:44.784Z

Link: CVE-2026-103649

cve-icon Vulnrichment

Updated: 2026-10-08T14:24:16.749Z

cve-icon NVD

Status : Received

Published: 2026-10-08T11:16:43.093

Modified: 2026-10-08T15:17:31.740

Link: CVE-2026-103649

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T12:30:04Z

Weaknesses
  • CWE-1088

    Synchronous Access of Remote Resource without Timeout