Description
Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadratic in the command's length or in the number of elements it names, and can be made to hold memory out of proportion to a command. The FETCH data-item parser normalised a BODY[] section with a case-insensitive string replacement that copied the whole item per occurrence and split the item list by repeatedly copying the remainder of the command; the server's case-insensitive search compared a needle afresh at every position, so a long SEARCH TEXT key over a message cost the product of the two lengths; SEARCH message sets and the saved-result marker ($), SORT criteria, HEADER.FIELDS name lists and UID ranges were each read once per message rather than once per command; and a FETCH naming a message's sections very many times read and held every section in memory before sending any. An IMAP command may continue past one line through non-synchronizing literals, so one command can reach about eleven megabytes. The IMAP worker threads are a small pool shared with SMTP and POP3, so a signed-in user sending such commands can make the IMAP, SMTP and POP3 services stop responding (CWE-407) and can consume excessive memory (CWE-400).
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service (DoS) impacting IMAP, SMTP, and POP3 services
Action: Immediate Patch
AI Analysis

Impact

hMailServer 6.0.0 through 6.3.5 processes various IMAP commands with quadratic time and memory complexity. Commands such as FETCH, SEARCH, SORT, and HEADER.FIELDS perform multiple passes over the input or the message, repeatedly copying data and comparing strings in a case‑insensitive manner. As a result a single signed‑in user can craft commands that consume memory out of proportion to the command size and halt the server’s I/O threads, causing the IMAP, SMTP, and POP3 services to stop responding.

Affected Systems

The vulnerability affects Progressive Robot Ltd’s hMailServer product in all releases from version 6.0.0 up to, but not including, 6.3.6. The official fix is available in hMailServer 6.3.6, which rewrites command parsing to perform single‑pass operations, limits memory usage per command, and rejects oversized FETCH instructions before any data is returned.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. EPSS is not available and the flaw is not listed in CISA’s KEV catalog, so it is currently considered a lower exploitation probability. However, the attack requires a valid signed‑in account, and the shared worker pool means that a single malicious user can cause a denial of service across all mail protocols. The vendor solution is to upgrade to 6.3.6; otherwise restricting IMAP access to trusted accounts and networks can reduce the attack surface.

Generated by OpenCVE AI on October 8, 2026 at 13:20 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, which parses the FETCH command and runs the server's case-insensitive string operations in a single pass, reads each SEARCH and UID set and HEADER.FIELDS list once per command, substitutes the saved-result marker once, and refuses a FETCH whose sections add up to many times the message before sending any. There is no configuration workaround; the commands require only a signed-in account. Restricting IMAP access to trusted accounts and networks reduces who can send them.


OpenCVE Recommended Actions

  • Upgrade hMailServer to version 6.3.6 or later to apply the vendor-published fix
  • Configure the mail server to allow IMAP connections only from trusted accounts and networks, limiting who can issue large or complex commands
  • Monitor memory usage and service responsiveness to detect and contain any denial-of-service attempts

Generated by OpenCVE AI on October 8, 2026 at 13:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Progressive Robot
Progressive Robot hmailserver
Vendors & Products Progressive Robot
Progressive Robot hmailserver

Thu, 08 Oct 2026 12:00:00 +0000

Type Values Removed Values Added
Description Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadratic in the command's length or in the number of elements it names, and can be made to hold memory out of proportion to a command. The FETCH data-item parser normalised a BODY[] section with a case-insensitive string replacement that copied the whole item per occurrence and split the item list by repeatedly copying the remainder of the command; the server's case-insensitive search compared a needle afresh at every position, so a long SEARCH TEXT key over a message cost the product of the two lengths; SEARCH message sets and the saved-result marker ($), SORT criteria, HEADER.FIELDS name lists and UID ranges were each read once per message rather than once per command; and a FETCH naming a message's sections very many times read and held every section in memory before sending any. An IMAP command may continue past one line through non-synchronizing literals, so one command can reach about eleven megabytes. The IMAP worker threads are a small pool shared with SMTP and POP3, so a signed-in user sending such commands can make the IMAP, SMTP and POP3 services stop responding (CWE-407) and can consume excessive memory (CWE-400).
Title Inefficient Algorithmic Complexity in hMailServer
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Progressive Robot Hmailserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T14:19:53.760Z

Reserved: 2026-10-08T10:52:10.640Z

Link: CVE-2026-107581

cve-icon Vulnrichment

Updated: 2026-10-08T14:19:01.806Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T12:17:16.320

Modified: 2026-10-08T21:02:43.860

Link: CVE-2026-107581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T13:30:18Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity