Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to hMailServer 6.3.6, in which each account or administrator holds at most fifty sessions and gives up its own least recently used one, and a full table makes room out of the sessions of whoever holds the most. Until then: limit the rate of POST /api/v1/session per client at a reverse proxy in front of the listener, and disable an account found signing in repeatedly (its sign-ins are in the application log and its device list).
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled eviction in the browser session table of the REST API in Progressive Robot hMailServer 6.2.28 through 6.3.5 allows a remote authenticated user to end other users' sessions. The table of browser sessions, shared by every account, the server administrator and support sessions, dropped its least recently used session whenever it was full, whoever it belonged to, and placed no limit on how many sessions one account could hold. A user who repeatedly signs in with their own mailbox password can therefore keep the table full and sign out every webmail and administration session that is idle for more than a short time, for as long as they continue. | |
| Title | Allocation of Resources Without Limits or Throttling in hMailServer | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-10-08T19:12:52.460Z
Reserved: 2026-10-08T10:52:35.638Z
Link: CVE-2026-107586
No data.
Status : Received
Published: 2026-10-08T15:17:44.897
Modified: 2026-10-08T20:17:34.713
Link: CVE-2026-107586
No data.
OpenCVE Enrichment
Updated: 2026-10-08T17:30:17Z
-
CWE-770
Allocation of Resources Without Limits or Throttling