Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadratic in the command's length or in the number of elements it names, and can be made to hold memory out of proportion to a command. The FETCH data-item parser normalised a BODY[] section with a case-insensitive string replacement that copied the whole item per occurrence and split the item list by repeatedly copying the remainder of the command; the server's case-insensitive search compared a needle afresh at every position, so a long SEARCH TEXT key over a message cost the product of the two lengths; SEARCH message sets and the saved-result marker ($), SORT criteria, HEADER.FIELDS name lists and UID ranges were each read once per message rather than once per command; and a FETCH naming a message's sections very many times read and held every section in memory before sending any. An IMAP command may continue past one line through non-synchronizing literals, so one command can reach about eleven megabytes. The IMAP worker threads are a small pool shared with SMTP and POP3, so a signed-in user sending such commands can make the IMAP, SMTP and POP3 services stop responding (CWE-407) and can consume excessive memory (CWE-400).
Advisories

No advisories yet.

Fixes

Solution

Upgrade to hMailServer 6.3.6, which parses the FETCH command and runs the server's case-insensitive string operations in a single pass, reads each SEARCH and UID set and HEADER.FIELDS list once per command, substitutes the saved-result marker once, and refuses a FETCH whose sections add up to many times the message before sending any. There is no configuration workaround; the commands require only a signed-in account. Restricting IMAP access to trusted accounts and networks reduces who can send them.


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Progressive Robot
Progressive Robot hmailserver
Vendors & Products Progressive Robot
Progressive Robot hmailserver

Thu, 08 Oct 2026 12:00:00 +0000

Type Values Removed Values Added
Description Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadratic in the command's length or in the number of elements it names, and can be made to hold memory out of proportion to a command. The FETCH data-item parser normalised a BODY[] section with a case-insensitive string replacement that copied the whole item per occurrence and split the item list by repeatedly copying the remainder of the command; the server's case-insensitive search compared a needle afresh at every position, so a long SEARCH TEXT key over a message cost the product of the two lengths; SEARCH message sets and the saved-result marker ($), SORT criteria, HEADER.FIELDS name lists and UID ranges were each read once per message rather than once per command; and a FETCH naming a message's sections very many times read and held every section in memory before sending any. An IMAP command may continue past one line through non-synchronizing literals, so one command can reach about eleven megabytes. The IMAP worker threads are a small pool shared with SMTP and POP3, so a signed-in user sending such commands can make the IMAP, SMTP and POP3 services stop responding (CWE-407) and can consume excessive memory (CWE-400).
Title Inefficient Algorithmic Complexity in hMailServer
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T14:19:53.760Z

Reserved: 2026-10-08T10:52:10.640Z

Link: CVE-2026-107581

cve-icon Vulnrichment

Updated: 2026-10-08T14:19:01.806Z

cve-icon NVD

Status : Received

Published: 2026-10-08T12:17:16.320

Modified: 2026-10-08T15:17:44.413

Link: CVE-2026-107581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T13:30:18Z

Weaknesses