Impact
A non‑terminating loop exists in the MIME processing of received messages in Progressive Robot hMailServer versions 6.0.0 through 6.3.5. Triggered by removing a MIME header parameter whose value is empty and immediately followed by a semicolon, the loop never ends, locking a worker thread until the service is restarted. This represents a CWE-835 weakness (Infinite Loop). Additionally, decoding header fields with many RFC 2047 encoded words of non‑standard encodings or removing parameters with many RFC 2231 continuations consumes time that grows quadratically with the message size, overloading the small thread pools that handle IMAP, SMTP, POP3, delivery, and REST API traffic.
Affected Systems
The vulnerability affects hMailServer from Progressive Robot Ltd, specifically versions 6.0.0 through 6.3.5. All standard mail service components—IMAP, SMTP, POP3, and the REST API—are impacted by the flaw.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, and the exploit is feasible via any remote unauthenticated attacker who can send a crafted message or use the REST API. The fault causes a DoS by exhausting a worker thread with an endless loop and by slowing down processing with quadratic delays. EPSS data is not available, and the flaw is not listed in CISA KEV, but the lack of authentication and wide reach make it a significant risk for exposed instances.
OpenCVE Enrichment