Description
Inefficient algorithmic complexity and a non-terminating loop in the MIME processing of received messages in Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote unauthenticated attacker to make the mail services unavailable by sending a message. Removing a MIME header parameter whose value is empty and directly followed by a semicolon (for example a Content-Disposition with 'filename=a.bat; filename=;') entered a loop that never terminates, holding a worker thread at full load until the server is restarted; this is reached when the attachment blocker renames a blocked attachment or a filename is set over the REST API. Separately, decoding a header field that holds many RFC 2047 encoded words of an encoding other than base64 or quoted-printable, removing a parameter with many RFC 2231 continuations, and deleting many header fields of one name each took time growing with the square of the message, on the small thread pools that serve IMAP, SMTP and POP3 connections, delivery and the REST API.
Published: 2026-10-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

A non‑terminating loop exists in the MIME processing of received messages in Progressive Robot hMailServer versions 6.0.0 through 6.3.5. Triggered by removing a MIME header parameter whose value is empty and immediately followed by a semicolon, the loop never ends, locking a worker thread until the service is restarted. This represents a CWE-835 weakness (Infinite Loop). Additionally, decoding header fields with many RFC 2047 encoded words of non‑standard encodings or removing parameters with many RFC 2231 continuations consumes time that grows quadratically with the message size, overloading the small thread pools that handle IMAP, SMTP, POP3, delivery, and REST API traffic.

Affected Systems

The vulnerability affects hMailServer from Progressive Robot Ltd, specifically versions 6.0.0 through 6.3.5. All standard mail service components—IMAP, SMTP, POP3, and the REST API—are impacted by the flaw.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, and the exploit is feasible via any remote unauthenticated attacker who can send a crafted message or use the REST API. The fault causes a DoS by exhausting a worker thread with an endless loop and by slowing down processing with quadratic delays. EPSS data is not available, and the flaw is not listed in CISA KEV, but the lack of authentication and wide reach make it a significant risk for exposed instances.

Generated by OpenCVE AI on October 8, 2026 at 13:54 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, which removes a MIME parameter and deletes header fields in a single pass and searches an encoded word's terminator only for a decodable word. Until then: lower the maximum message size (which bounds the quadratic paths but not the non-terminating one), and restart the service to end a hung thread.


OpenCVE Recommended Actions

  • Upgrade to hMailServer 6.3.6, which removes the problematic MIME parameter handling and optimizes header parsing.
  • If an upgrade is not immediately possible, lower the maximum message size to bound the quadratic processing paths.
  • Restart the hMailServer service to terminate any hung threads caused by the loop.

Generated by OpenCVE AI on October 8, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Progressive Robot
Progressive Robot hmailserver
Vendors & Products Progressive Robot
Progressive Robot hmailserver

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 12:00:00 +0000

Type Values Removed Values Added
Description Inefficient algorithmic complexity and a non-terminating loop in the MIME processing of received messages in Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote unauthenticated attacker to make the mail services unavailable by sending a message. Removing a MIME header parameter whose value is empty and directly followed by a semicolon (for example a Content-Disposition with 'filename=a.bat; filename=;') entered a loop that never terminates, holding a worker thread at full load until the server is restarted; this is reached when the attachment blocker renames a blocked attachment or a filename is set over the REST API. Separately, decoding a header field that holds many RFC 2047 encoded words of an encoding other than base64 or quoted-printable, removing a parameter with many RFC 2231 continuations, and deleting many header fields of one name each took time growing with the square of the message, on the small thread pools that serve IMAP, SMTP and POP3 connections, delivery and the REST API.
Title Loop with Unreachable Exit Condition ('Infinite Loop') in hMailServer
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Progressive Robot Hmailserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T14:17:33.868Z

Reserved: 2026-10-08T10:51:50.638Z

Link: CVE-2026-107577

cve-icon Vulnrichment

Updated: 2026-10-08T14:17:29.516Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T12:17:15.630

Modified: 2026-10-08T21:02:43.860

Link: CVE-2026-107577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T07:30:17Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')