Impact
Missing network timeouts in the Linux builds cause server threads to hang indefinitely when a remote peer accepts a connection and then sends no data. The result is a denial of service that blocks outbound mail delivery, as the server cannot finish processing the request. This flaw also applies to several components that perform network requests, such as MTA‑STS policy fetching, DANE TLSA queries, OAuth2 token requests, ACME client operations, and the ManageSieve and metrics listeners.
Affected Systems
The vulnerability affects Progressive Robot Ltd’s hMailServer versions 6.3.0 through 6.3.5 running on Linux; Windows builds are not impacted. The flaw manifests in components that perform synchronous remote calls, including the embedded HTTP client used for policy and credential retrieval and the listeners that respond to client connections.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity denial of service. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a remote attacker who can interact with the hMailServer instance over the network and in some cases control the recipient domain of the outbound message. Based on the description, the likely attack vector is remote network access to the Linux host running hMailServer. The risk is moderate to high due to the impact on mail delivery and potential cascading denial of service for users.
OpenCVE Enrichment