Description
Inefficient complexity in the Sieve filter evaluation of Progressive Robot hMailServer 6.2.24 through 6.3.5 allows an authenticated account holder to make the mail services unavailable with their own filter. A ':matches' pattern was matched by a backtracking descent whose time grew with the matched value's length raised to the number of wildcards, so a pattern such as '*a*a*a*b' over 800 characters took 44 seconds; and 'deleteheader' erased the fields it removed one at a time, so removing many fields of one name over a message's header cost O(N^2) (80,000 fields took 18.8 seconds). Sieve filters run on the small, shared delivery thread pool, so an account holder whose active script does this, fed a few messages they can send themselves, empties the pool and stops delivery for the whole server. The script is the account holder's own and cannot be set for another user.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

This vulnerability focuses on inefficient regular expression handling within the Sieve filter engine of hMailServer. An authenticated user can construct a ':matches' expression containing multiple wildcards or use a 'deleteheader' command that deletes header fields one by one. Because the processing time scales exponentially with the number of wildcards and quadratically with the number of headers removed, an attacker can consume excessive CPU resources. As Sieve scripts run on a shared delivery thread pool, a single account that forces slow processing can exhaust the pool, causing mail delivery to cease for all users, resulting in a denial of service.

Affected Systems

The issue impacts Progressive Robot Ltd's hMailServer versions 6.2.24 through 6.3.5. The vendor has released 6.3.6, which mitigates the back‑tracking and single‑pass deletion flaws. Systems running any earlier patch level are vulnerable until the update is applied.

Risk and Exploitability

With a CVSS score of 6.5, the vulnerability is moderate. It requires an authenticated account that can execute Sieve scripts, but the attacker can generate the needed traffic themselves. While the EPSS score is unavailable, the serious exhaustion of the delivery thread pool means that once triggered the denial of service is immediate. The vulnerability is not currently listed in CISA’s KEV catalog, and there are no known remote exploitation vectors beyond the authenticated local context.

Generated by OpenCVE AI on October 8, 2026 at 13:24 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, which matches a ':matches' pattern by placing each piece once (time linear in the value times the pattern) and removes 'deleteheader' fields in one pass. Until then, review active Sieve scripts for ':matches' patterns with several wildcards and for 'deleteheader', and lower the maximum message size.


OpenCVE Recommended Actions

  • Update to hMailServer 6.3.6 to eliminate back‑tracking and quadratic deleteheader behavior.
  • If an immediate upgrade is not feasible, review and simplify active Sieve scripts: remove ':matches' patterns with many wildcards, limit 'deleteheader' usage, and reduce the maximum message size processed by the server.
  • Consider temporarily disabling Sieve scripting for non‑essential accounts or implementing a watchdog to restart the delivery thread pool if resource usage spikes.
  • Monitor mail queue metrics and thread pool usage to detect early signs of denial‑of‑service activity.

Generated by OpenCVE AI on October 8, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Progressive Robot
Progressive Robot hmailserver
Vendors & Products Progressive Robot
Progressive Robot hmailserver

Thu, 08 Oct 2026 12:00:00 +0000

Type Values Removed Values Added
Description Inefficient complexity in the Sieve filter evaluation of Progressive Robot hMailServer 6.2.24 through 6.3.5 allows an authenticated account holder to make the mail services unavailable with their own filter. A ':matches' pattern was matched by a backtracking descent whose time grew with the matched value's length raised to the number of wildcards, so a pattern such as '*a*a*a*b' over 800 characters took 44 seconds; and 'deleteheader' erased the fields it removed one at a time, so removing many fields of one name over a message's header cost O(N^2) (80,000 fields took 18.8 seconds). Sieve filters run on the small, shared delivery thread pool, so an account holder whose active script does this, fed a few messages they can send themselves, empties the pool and stops delivery for the whole server. The script is the account holder's own and cannot be set for another user.
Title Inefficient Regular Expression Complexity in hMailServer
Weaknesses CWE-1333
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Progressive Robot Hmailserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T17:35:21.719Z

Reserved: 2026-10-08T10:51:25.637Z

Link: CVE-2026-107572

cve-icon Vulnrichment

Updated: 2026-10-08T17:35:14.413Z

cve-icon NVD

Status : Received

Published: 2026-10-08T12:17:14.870

Modified: 2026-10-08T18:17:24.790

Link: CVE-2026-107572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T13:30:18Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity