Description
Uncontrolled eviction in the browser session table of the REST API in Progressive Robot hMailServer 6.2.28 through 6.3.5 allows a remote authenticated user to end other users' sessions. The table of browser sessions, shared by every account, the server administrator and support sessions, dropped its least recently used session whenever it was full, whoever it belonged to, and placed no limit on how many sessions one account could hold. A user who repeatedly signs in with their own mailbox password can therefore keep the table full and sign out every webmail and administration session that is idle for more than a short time, for as long as they continue.
Published: 2026-10-08
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service through forced session termination
Action: Apply patch
AI Analysis

Impact

The flaw is an uncontrolled eviction of older entries in the shared browser session table of the REST API. When the table reaches capacity it removes the least‑recently used entry regardless of the owning account, and it imposes no upper bound on how many sessions a single account can create. As a result, a user with valid credentials can flood the server with logins using their own mailbox password, keep the table full, and cause any idle session belonging to other users—including webmail, administrative, or support consoles—to be evicted. This produces a denial‑of‑service condition by forcing other users out of context and potentially disrupting ongoing operations.

Affected Systems

The vulnerability exists in Progressive Robot Ltd’s hMailServer, affecting all installations of versions 6.2.28 through 6.3.5. The issue is specific to the REST API endpoint for managing browser sessions, which is shared among all accounts, the server administrator, and support sessions.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate impact; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires remote authenticated access to the REST API and repeated POST requests to /api/v1/session. Once the attacker has a valid account, they can maintain a flooded session table by repeatedly signing in, thereby expiring other users’ idle sessions. No public exploits are documented, but the inherent nature of the flaw allows an attacker in possession of any valid user credential to cause service interruption.

Generated by OpenCVE AI on October 8, 2026 at 17:16 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, in which each account or administrator holds at most fifty sessions and gives up its own least recently used one, and a full table makes room out of the sessions of whoever holds the most. Until then: limit the rate of POST /api/v1/session per client at a reverse proxy in front of the listener, and disable an account found signing in repeatedly (its sign-ins are in the application log and its device list).


OpenCVE Recommended Actions

  • Upgrade to hMailServer 6.3.6 which limits sessions per account to fifty and evicts based on least recently used across all sessions
  • Place a rate limit on POST /api/v1/session requests per client at the reverse proxy level to prevent one account from flooding the table
  • Disable or lock any account that repeatedly signs in more than a normal threshold, and monitor the application log for repeated sign‑in activity

Generated by OpenCVE AI on October 8, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Description Uncontrolled eviction in the browser session table of the REST API in Progressive Robot hMailServer 6.2.28 through 6.3.5 allows a remote authenticated user to end other users' sessions. The table of browser sessions, shared by every account, the server administrator and support sessions, dropped its least recently used session whenever it was full, whoever it belonged to, and placed no limit on how many sessions one account could hold. A user who repeatedly signs in with their own mailbox password can therefore keep the table full and sign out every webmail and administration session that is idle for more than a short time, for as long as they continue.
Title Allocation of Resources Without Limits or Throttling in hMailServer
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T19:12:52.460Z

Reserved: 2026-10-08T10:52:35.638Z

Link: CVE-2026-107586

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T15:17:44.897

Modified: 2026-10-08T21:02:43.860

Link: CVE-2026-107586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:30:17Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling