Description
Inefficient algorithmic complexity in the decoding of message header fields in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the IMAP, SMTP and POP3 services, or the webmail, unavailable by sending a message. The server unfolded a decoded header value by finding each line break from the end of the value and removing it, moving the rest of the value each time, so its work grew with the square of the number of line breaks, and an RFC 2047 encoded word may decode to any number of them. A received message whose Subject or other header field holds such a value keeps a worker thread busy for minutes or longer each time the value is read: when the recipient's IMAP client searches, sorts or threads the folder by a header, when the webmail lists the folder, and, where configured, when a rule tests a header, a spam tag is added to the Subject or an abuse report is read during delivery. The IMAP worker threads are shared with SMTP and POP3, so a few such messages stop those services responding. The server's reading of a message header from its file also searched everything read so far after each 4,000 bytes, costing seconds for a header of tens of megabytes.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Patch Now
AI Analysis

Impact

Progressive Robot hMailServer 6.0.0 through 6.3.5 implements a header decoding routine that repeatedly scans the header from the end, moving data each time a line break is found. The time required grows roughly with the square of the number of line breaks in the decoded value, and an RFC 2047 encoded word can produce an arbitrary number of such breaks. As a result, a message with a specially crafted Subject or other header can cause a worker thread to spend minutes or longer processing that header each time it is read. The affected services—IMAP, SMTP, POP3, and webmail—share worker threads, so a single problematic message can halt all of them and also delay operations such as searching, sorting, threading, rule evaluation, and spam tag generation.

Affected Systems

The vulnerability affects all releases of hMailServer from 6.0.0 up to and including 6.3.5, regardless of platform. All primary mail protocols (IMAP, SMTP, POP3) and the webmail interface are impacted, as well as any rule or abuse reporting mechanisms that scan message headers. The issue is triggered when a message is received and later accessed by any of these interfaces.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity risk, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote and unauthenticated: an adversary can send a crafted message containing a large RFC 2047 encoded header field to the vulnerable server. Once the header is parsed, the server spends excessive CPU time, effectively denying service to all users interacting with that server. Because the exploitation does not require authentication, the impact scope spans any client using the affected protocols or webmail interface.

Generated by OpenCVE AI on October 8, 2026 at 13:21 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, which unfolds a header value in one pass and searches a header being read only in what each read adds. Until then: lower the maximum message size, which bounds the cost (it grows with the square of the value's size); remove such a message over POP3; or keep the REST listener off (RestApiPort 0, the default).


OpenCVE Recommended Actions

  • Upgrade to hMailServer 6.3.6, which fixes the quadratic header decoding logic.
  • If an upgrade cannot be performed immediately, reduce the maximum message size configured in the server to bound the processing cost.
  • Disable the REST listener by setting RestApiPort to 0 and delete any messages that trigger heavy header decoding via POP3 or by removing them from the mailbox.

Generated by OpenCVE AI on October 8, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Progressive Robot
Progressive Robot hmailserver
Vendors & Products Progressive Robot
Progressive Robot hmailserver

Thu, 08 Oct 2026 12:00:00 +0000

Type Values Removed Values Added
Description Inefficient algorithmic complexity in the decoding of message header fields in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the IMAP, SMTP and POP3 services, or the webmail, unavailable by sending a message. The server unfolded a decoded header value by finding each line break from the end of the value and removing it, moving the rest of the value each time, so its work grew with the square of the number of line breaks, and an RFC 2047 encoded word may decode to any number of them. A received message whose Subject or other header field holds such a value keeps a worker thread busy for minutes or longer each time the value is read: when the recipient's IMAP client searches, sorts or threads the folder by a header, when the webmail lists the folder, and, where configured, when a rule tests a header, a spam tag is added to the Subject or an abuse report is read during delivery. The IMAP worker threads are shared with SMTP and POP3, so a few such messages stop those services responding. The server's reading of a message header from its file also searched everything read so far after each 4,000 bytes, costing seconds for a header of tens of megabytes.
Title Inefficient Algorithmic Complexity in hMailServer
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Progressive Robot Hmailserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T14:20:26.210Z

Reserved: 2026-10-08T10:52:05.641Z

Link: CVE-2026-107580

cve-icon Vulnrichment

Updated: 2026-10-08T14:20:22.811Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T12:17:16.123

Modified: 2026-10-08T21:02:43.860

Link: CVE-2026-107580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T14:00:05Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity