Description
Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the mail services unavailable by sending a message. Building the canonical header and choosing the header fields named in a signature's h= tag took time growing with the square of the message's header: the 'simple' canonicalisation prepended each continuation line of a folded field to the lines already gathered, and both canonicalisations searched the gathered fields from the bottom for each h= name and erased the match from the middle of the list. A message whose header holds very many fields, or a field folded over very many lines, with a DKIM-Signature the attacker signs for a domain they control, keeps a worker thread busy for tens of seconds per signature; up to ten signatures are evaluated per message by each of the DKIM and DMARC tests, on the threads that serve delivery and SMTP.
Published: 2026-10-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

Inefficient algorithmic complexity in hMailServer’s inbound DKIM and ARC signature verification allows a remote, unauthenticated attacker to occupy server resources by sending crafted emails with extensive header fields and multiple DKIM signatures. The canonical header construction and field lookup operations scale quadratically with header size, causing each worker thread to remain busy for tens of seconds per signature. This attack can render mail delivery and SMTP services unavailable, disrupting business communication and potentially leading to loss of critical email traffic.

Affected Systems

The vulnerability affects Progressive Robot Ltd’s hMailServer versions 6.0.0 through 6.3.5. These releases process DKIM and ARC signatures with an algorithm that can be forced to consume excessive CPU time by exploiting large or heavily folded header fields. Email services running these affected versions are at risk when receiving messages from domains that can be controlled by an attacker.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote via SMTP, requiring only an unauthenticated message that includes a DKIM signature for an attacker‑controlled domain. Because the algorithmic cost grows with the square of the header size, an attacker can reliably exhaust server resources by crafting emails with numerous header fields or heavily folded lines. The timely application of the patch in version 6.3.6 mitigates the issue by building the canonical header in a single pass and selecting header fields by name from an index.

Generated by OpenCVE AI on October 8, 2026 at 13:22 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, which builds the canonical header in one pass and chooses the h= fields from an index by name. Until then, lower the maximum message size, which bounds the cost.


OpenCVE Recommended Actions

  • Upgrade to hMailServer 6.3.6, which implements a single‑pass canonical header construction and indexed header field selection.
  • If an upgrade is not immediately possible, lower the maximum message size to bound the potential cost of processing large headers.
  • Ensure that SMTP and mail delivery systems enforce message size limits to prevent oversized messages from triggering the vulnerable routines.

Generated by OpenCVE AI on October 8, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Progressive Robot
Progressive Robot hmailserver
Vendors & Products Progressive Robot
Progressive Robot hmailserver

Thu, 08 Oct 2026 12:00:00 +0000

Type Values Removed Values Added
Description Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the mail services unavailable by sending a message. Building the canonical header and choosing the header fields named in a signature's h= tag took time growing with the square of the message's header: the 'simple' canonicalisation prepended each continuation line of a folded field to the lines already gathered, and both canonicalisations searched the gathered fields from the bottom for each h= name and erased the match from the middle of the list. A message whose header holds very many fields, or a field folded over very many lines, with a DKIM-Signature the attacker signs for a domain they control, keeps a worker thread busy for tens of seconds per signature; up to ten signatures are evaluated per message by each of the DKIM and DMARC tests, on the threads that serve delivery and SMTP.
Title Inefficient Algorithmic Complexity in hMailServer
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Progressive Robot Hmailserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T14:15:09.064Z

Reserved: 2026-10-08T10:51:45.640Z

Link: CVE-2026-107576

cve-icon Vulnrichment

Updated: 2026-10-08T14:15:05.682Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T12:17:15.487

Modified: 2026-10-08T21:02:43.860

Link: CVE-2026-107576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T13:30:18Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity