Impact
This vulnerability focuses on inefficient regular expression handling within the Sieve filter engine of hMailServer. An authenticated user can construct a ':matches' expression containing multiple wildcards or use a 'deleteheader' command that deletes header fields one by one. Because the processing time scales exponentially with the number of wildcards and quadratically with the number of headers removed, an attacker can consume excessive CPU resources. As Sieve scripts run on a shared delivery thread pool, a single account that forces slow processing can exhaust the pool, causing mail delivery to cease for all users, resulting in a denial of service.
Affected Systems
The issue impacts Progressive Robot Ltd's hMailServer versions 6.2.24 through 6.3.5. The vendor has released 6.3.6, which mitigates the back‑tracking and single‑pass deletion flaws. Systems running any earlier patch level are vulnerable until the update is applied.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability is moderate. It requires an authenticated account that can execute Sieve scripts, but the attacker can generate the needed traffic themselves. While the EPSS score is unavailable, the serious exhaustion of the delivery thread pool means that once triggered the denial of service is immediate. The vulnerability is not currently listed in CISA’s KEV catalog, and there are no known remote exploitation vectors beyond the authenticated local context.
OpenCVE Enrichment