Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to hMailServer 6.3.6, in which the route reads a message's HTML once to find the images it names and once to write them, and writes at most 24 MB of inlined images in all, every reference counted. Until then: lower the maximum message size, which bounds the cost (it grows with the square of the HTML's size); leave the webmail's offline store off so that only an opened message triggers it; or keep the REST listener off (RestApiPort 0, the default).
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progressive Robot
Progressive Robot hmailserver |
|
| Vendors & Products |
Progressive Robot
Progressive Robot hmailserver |
Thu, 08 Oct 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. The route that renders a received message's HTML replaced each reference to an embedded image in place, with work that grew with the square of the number of references, and wrote the image out for every reference while counting it against its size limit only once. A message whose HTML refers to one small embedded image a very large number of times, opened in the webmail by its recipient, therefore keeps one of the listener's four worker threads busy for minutes and makes it build a document of gigabytes, so that a few such messages leave the HTTP listener unable to answer anybody. | |
| Title | Inefficient Algorithmic Complexity in hMailServer | |
| Weaknesses | CWE-407 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-10-08T14:14:10.184Z
Reserved: 2026-10-08T10:52:20.637Z
Link: CVE-2026-107583
Updated: 2026-10-08T14:14:05.892Z
Status : Received
Published: 2026-10-08T12:17:16.633
Modified: 2026-10-08T15:17:44.647
Link: CVE-2026-107583
No data.
OpenCVE Enrichment
Updated: 2026-10-08T13:45:05Z
-
CWE-407
Inefficient Algorithmic Complexity