Description
Uncontrolled eviction in the pending sign-in tables of the REST API in Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to make other users' OpenID Connect, SAML and passkey sign-ins fail. The routes that start a single sign-on and hand out a passkey sign-in challenge are reached without authentication and stored pending state in bounded tables that dropped their oldest entry when full, whoever had started it. An attacker who starts sign-ins a few times a second (about a hundred a second for passkeys) pushes every other user's pending sign-in out of the table before that user's browser returns, denying single sign-on and passkey sign-in for as long as the requests continue.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability permits a remote attacker to flood the pending sign‑in tables used for OpenID Connect, SAML and passkey authentication. By continuously initiating single‑sign‑on and passkey challenge requests without authentication, the attacker forces the bounded tables to evict older entries, effectively blocking legitimate users from completing their authentication and denying them access to email services. It is a CWE-770 allocation of resources without limits or throttling.

Affected Systems

Affected are Progressive Robot Ltd hMailServer versions 6.3.4 and 6.3.5. These releases expose REST API endpoints that handle SSO and passkey start operations. The problem is absent in later 6.3.6 release.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and EPSS is not reported, so current evidence of exploitation is limited. However, the vulnerability is exploitable remotely without authentication and can be leveraged to induce a denial of service on authentication services. The attacker can start requests at a rate of a few times per second—around a hundred per second for passkey challenges—causing other users’ pending sign‑ins to be evicted. The vulnerability is not listed in the CISA KEV catalogue as of this data.

Generated by OpenCVE AI on October 8, 2026 at 17:57 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, in which a pending OpenID Connect, SAML or passkey sign-in is no longer held on the server at all but carried by the browser in a cookie sealed with AES-256-GCM under a key held only in memory and good once, so there is no table a flood of unauthenticated starts can fill. Until then: limit the rate of /portal/oidc/start, /portal/saml/start and /api/v1/passkeys/challenge per client at a reverse proxy, and keep password sign-in available for administrators.


OpenCVE Recommended Actions

  • Upgrade to hMailServer 6.3.6
  • Implement rate limiting on /portal/oidc/start, /portal/saml/start and /api/v1/passkeys/challenge at the reverse proxy
  • Maintain password sign‑in for administrators to avoid authentication outages

Generated by OpenCVE AI on October 8, 2026 at 17:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Progressive Robot
Progressive Robot hmailserver
Vendors & Products Progressive Robot
Progressive Robot hmailserver

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Description Uncontrolled eviction in the pending sign-in tables of the REST API in Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to make other users' OpenID Connect, SAML and passkey sign-ins fail. The routes that start a single sign-on and hand out a passkey sign-in challenge are reached without authentication and stored pending state in bounded tables that dropped their oldest entry when full, whoever had started it. An attacker who starts sign-ins a few times a second (about a hundred a second for passkeys) pushes every other user's pending sign-in out of the table before that user's browser returns, denying single sign-on and passkey sign-in for as long as the requests continue.
Title Allocation of Resources Without Limits or Throttling in hMailServer
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Progressive Robot Hmailserver
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T19:13:35.529Z

Reserved: 2026-10-08T10:52:30.638Z

Link: CVE-2026-107585

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:44.763

Modified: 2026-10-08T20:17:34.590

Link: CVE-2026-107585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:00:02Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling