Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade to hMailServer 6.3.6, which builds the canonical header in one pass and chooses the h= fields from an index by name. Until then, lower the maximum message size, which bounds the cost.
Workaround
No workaround given by the vendor.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progressive Robot
Progressive Robot hmailserver |
|
| Vendors & Products |
Progressive Robot
Progressive Robot hmailserver |
Thu, 08 Oct 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the mail services unavailable by sending a message. Building the canonical header and choosing the header fields named in a signature's h= tag took time growing with the square of the message's header: the 'simple' canonicalisation prepended each continuation line of a folded field to the lines already gathered, and both canonicalisations searched the gathered fields from the bottom for each h= name and erased the match from the middle of the list. A message whose header holds very many fields, or a field folded over very many lines, with a DKIM-Signature the attacker signs for a domain they control, keeps a worker thread busy for tens of seconds per signature; up to ten signatures are evaluated per message by each of the DKIM and DMARC tests, on the threads that serve delivery and SMTP. | |
| Title | Inefficient Algorithmic Complexity in hMailServer | |
| Weaknesses | CWE-407 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-10-08T14:15:09.064Z
Reserved: 2026-10-08T10:51:45.640Z
Link: CVE-2026-107576
Updated: 2026-10-08T14:15:05.682Z
Status : Received
Published: 2026-10-08T12:17:15.487
Modified: 2026-10-08T15:17:43.817
Link: CVE-2026-107576
No data.
OpenCVE Enrichment
Updated: 2026-10-08T13:30:18Z