Impact
Inefficient algorithmic complexity in hMailServer's SPF macro expansion causes the server to repeatedly copy and trim labels when expanding a macro, turning a normally linear evaluation into a quadratic one. This logical flaw, classified as CWE‑407: Inefficient Algorithmic Complexity, can make the SPF validation of a message from the attacker’s domain take several seconds, consuming worker‑thread time and reducing overall availability. Based on the description, it is inferred that the attacker must publish a crafted SPF record containing a long macro expansion for a domain they control; once this record is queried, the delay occurs during inbound mail processing. The primary impact is a partial denial of service, as only messages that trigger the problematic SPF check experience latency and as the effect is bounded by SPF’s per‑term and per‑macro limits.
Affected Systems
Progressive Robot Ltd’s hMailServer versions 6.3.4 and 6.3.5 are affected. Both releases employ the same SPF macro‑expansion routine that can be exploited by an unauthenticated remote attacker who publishes a long‑expansion SPF record. No other releases are listed as vulnerable in the vendor’s advisory.
Risk and Exploitability
The CVSS score of 5.3 reflects the medium severity of the algorithmic inefficiency. EPSS is not available, and the vulnerability is not listed in CISA KEV. The attack can be performed by any remote host that can author an SPF record for a target domain, which is typically easy to obtain for a domain owner. Based on the description, it is inferred that the attacker must control the domain to publish the record; once the record is in place, the server will expend CPU time during processing, causing temporary delays. While exploitation requires only a crafted DNS record, the resulting availability loss is limited to messages that trigger the prolonged SPF check and is mitigated by SPF’s per‑term and per‑macro limits, keeping the overall risk moderate.
OpenCVE Enrichment