Impact
In the webmail message view of the REST API, Progressive Robot hMailServer processes the HTML of received messages by replacing each embedded image reference directly, performing work that grows with the square of the number of references and writing the image for every reference while counting its size only once. A crafted message that contains a single small image referenced many times causes the worker thread to spend minutes building a gigabyte‑sized document, rendering the HTTP listener unable to serve other requests. The flaw allows a remote, unauthenticated attacker to send such a message, causing the webmail, administration console, and REST API to become unavailable.
Affected Systems
Progressive Robot Ltd's hMailServer versions 6.3.2 through 6.3.5 are affected. The vulnerability exists in the webmail, administration console, and REST API components across these releases.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the exploit probability is not reported, but the flaw is remote and unauthenticated, meaning any user can trigger it by simply sending a specially crafted message. Although it is not listed in the CISA KEV catalog, the impact of interrupting mail services in an organization could be significant. The attacker only needs to place a message in the system; once opened by a recipient, the WebMail's rendering thread is engaged, causing service unavailability. Because the flaw is remote and does not require authentication or privileged access, the risk remains high for environments with the affected versions in production.
OpenCVE Enrichment