Impact
An inefficient algorithm used to read bounce notices and abuse reports in hMailServer 6.3.4 and 6.3.5 can consume quadratic time as the number of leading blank lines grows. Sending a specially crafted message that contains a very large number of blank lines in the headers of an incoming delivery status notification or abuse feedback report will cause the server to spend over a minute processing the delivery thread. The effect is a denial‑of‑service, preventing mail delivery to legitimate users while the thread is busy.
Affected Systems
Progressive Robot hMailServer versions 6.3.4 and 6.3.5 are affected whenever bounce processing or complaint processing is enabled or mailing lists are managed. These features are disabled by default, but can be turned on by the system administrator.
Risk and Exploitability
The vulnerability is scored CVSS 7.5 and currently has no EPSS score available. It is not listed in the CISA KEV catalog. It can be exploited by any remote unauthenticated attacker who has the ability to send SMTP messages to the server, making the likely attack vector an untrusted email boundary. The high resource consumption risk can affect the availability of the mail server, especially under load or if multiple crafted messages are sent in quick succession.
OpenCVE Enrichment