Impact
Inefficient algorithmic complexity in hMailServer’s inbound DKIM and ARC signature verification allows a remote, unauthenticated attacker to occupy server resources by sending crafted emails with extensive header fields and multiple DKIM signatures. The canonical header construction and field lookup operations scale quadratically with header size, causing each worker thread to remain busy for tens of seconds per signature. This attack can render mail delivery and SMTP services unavailable, disrupting business communication and potentially leading to loss of critical email traffic.
Affected Systems
The vulnerability affects Progressive Robot Ltd’s hMailServer versions 6.0.0 through 6.3.5. These releases process DKIM and ARC signatures with an algorithm that can be forced to consume excessive CPU time by exploiting large or heavily folded header fields. Email services running these affected versions are at risk when receiving messages from domains that can be controlled by an attacker.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote via SMTP, requiring only an unauthenticated message that includes a DKIM signature for an attacker‑controlled domain. Because the algorithmic cost grows with the square of the header size, an attacker can reliably exhaust server resources by crafting emails with numerous header fields or heavily folded lines. The timely application of the patch in version 6.3.6 mitigates the issue by building the canonical header in a single pass and selecting header fields by name from an index.
OpenCVE Enrichment