Description
Inefficient algorithmic complexity in the SPF macro expansion of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to consume worker-thread time by publishing a crafted SPF record. RFC 7208 section 7.1 requires a name too long to look up to lose whole labels from the left; the server did this by removing one label at a time and copying the rest of the name each time, so the work grew with the square of the expansion. An attacker who publishes an SPF record for a domain they control, with a mechanism whose domain-spec expands through macros to a name far longer than 253 characters, makes the SPF check of a message from that domain take several seconds. The expansion is bounded by SPF's own per-term and per-macro limits, so the loss of availability is partial.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Service Degradation
Action: Patch
AI Analysis

Impact

Inefficient algorithmic complexity in hMailServer's SPF macro expansion causes the server to repeatedly copy and trim labels when expanding a macro, turning a normally linear evaluation into a quadratic one. This logical flaw, classified as CWE‑407: Inefficient Algorithmic Complexity, can make the SPF validation of a message from the attacker’s domain take several seconds, consuming worker‑thread time and reducing overall availability. Based on the description, it is inferred that the attacker must publish a crafted SPF record containing a long macro expansion for a domain they control; once this record is queried, the delay occurs during inbound mail processing. The primary impact is a partial denial of service, as only messages that trigger the problematic SPF check experience latency and as the effect is bounded by SPF’s per‑term and per‑macro limits.

Affected Systems

Progressive Robot Ltd’s hMailServer versions 6.3.4 and 6.3.5 are affected. Both releases employ the same SPF macro‑expansion routine that can be exploited by an unauthenticated remote attacker who publishes a long‑expansion SPF record. No other releases are listed as vulnerable in the vendor’s advisory.

Risk and Exploitability

The CVSS score of 5.3 reflects the medium severity of the algorithmic inefficiency. EPSS is not available, and the vulnerability is not listed in CISA KEV. The attack can be performed by any remote host that can author an SPF record for a target domain, which is typically easy to obtain for a domain owner. Based on the description, it is inferred that the attacker must control the domain to publish the record; once the record is in place, the server will expend CPU time during processing, causing temporary delays. While exploitation requires only a crafted DNS record, the resulting availability loss is limited to messages that trigger the prolonged SPF check and is mitigated by SPF’s per‑term and per‑macro limits, keeping the overall risk moderate.

Generated by OpenCVE AI on October 8, 2026 at 14:27 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, which finds where the name becomes short enough and cuts it once. Until then, turn SPF checking off, or accept the bounded delay.


OpenCVE Recommended Actions

  • Upgrade hMailServer to version 6.3.6, which corrects the SPF macro expansion logic.
  • If an upgrade cannot be applied immediately, disable SPF checking for inbound mail to prevent the delay.
  • As a temporary measure, accept the bounded delay and monitor mail queues for any symptom of service degradation.

Generated by OpenCVE AI on October 8, 2026 at 14:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Progressive Robot
Progressive Robot hmailserver
Vendors & Products Progressive Robot
Progressive Robot hmailserver

Thu, 08 Oct 2026 12:00:00 +0000

Type Values Removed Values Added
Description Inefficient algorithmic complexity in the SPF macro expansion of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to consume worker-thread time by publishing a crafted SPF record. RFC 7208 section 7.1 requires a name too long to look up to lose whole labels from the left; the server did this by removing one label at a time and copying the rest of the name each time, so the work grew with the square of the expansion. An attacker who publishes an SPF record for a domain they control, with a mechanism whose domain-spec expands through macros to a name far longer than 253 characters, makes the SPF check of a message from that domain take several seconds. The expansion is bounded by SPF's own per-term and per-macro limits, so the loss of availability is partial.
Title Inefficient Algorithmic Complexity in hMailServer
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Progressive Robot Hmailserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T14:17:04.989Z

Reserved: 2026-10-08T10:51:40.639Z

Link: CVE-2026-107575

cve-icon Vulnrichment

Updated: 2026-10-08T14:17:00.390Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T12:17:15.333

Modified: 2026-10-08T21:02:43.860

Link: CVE-2026-107575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T14:30:18Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity