Impact
The vulnerability permits a remote attacker to flood the pending sign‑in tables used for OpenID Connect, SAML and passkey authentication. By continuously initiating single‑sign‑on and passkey challenge requests without authentication, the attacker forces the bounded tables to evict older entries, effectively blocking legitimate users from completing their authentication and denying them access to email services. It is a CWE-770 allocation of resources without limits or throttling.
Affected Systems
Affected are Progressive Robot Ltd hMailServer versions 6.3.4 and 6.3.5. These releases expose REST API endpoints that handle SSO and passkey start operations. The problem is absent in later 6.3.6 release.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and EPSS is not reported, so current evidence of exploitation is limited. However, the vulnerability is exploitable remotely without authentication and can be leveraged to induce a denial of service on authentication services. The attacker can start requests at a rate of a few times per second—around a hundred per second for passkey challenges—causing other users’ pending sign‑ins to be evicted. The vulnerability is not listed in the CISA KEV catalogue as of this data.
OpenCVE Enrichment