Impact
An inefficiency in hMailServer’s string replacement algorithm allows a remote, unauthenticated attacker to trigger a denial of service by sending an HTML‑only message containing a very large number of entity references. The server’s decoding routine runs in quadratic time, causing one of the REST or IMAP listener threads to become occupied for minutes or longer each time the infected message is listed. Consequently, the webmail interface, administration console, and REST API can be rendered unavailable without the victim opening the message.
Affected Systems
The vulnerability affects versions 6.3.3 through 6.3.5 of hMailServer’s REST API and versions 6.2.22 through 6.3.5 of the IMAP PREVIEW functionality in products from Progressive Robot Ltd.
Risk and Exploitability
With a CVSS score of 6.5 the flaw is considered moderate severity, and it is not currently tracked in CISA’s KEV catalog. Exploitation requires only network access to the affected ports; the attacker can send a crafted message remotely without authentication. Because the exploit leads to a prolonged service block of an individual listener thread, the impact is localized to webmail or IMAP clients, but repeated attacks can exhaust all listener threads and deny service to all users.
OpenCVE Enrichment