Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade to hMailServer 6.3.6, which parses the FETCH command and runs the server's case-insensitive string operations in a single pass, reads each SEARCH and UID set and HEADER.FIELDS list once per command, substitutes the saved-result marker once, and refuses a FETCH whose sections add up to many times the message before sending any. There is no configuration workaround; the commands require only a signed-in account. Restricting IMAP access to trusted accounts and networks reduces who can send them.
Workaround
No workaround given by the vendor.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progressive Robot
Progressive Robot hmailserver |
|
| Vendors & Products |
Progressive Robot
Progressive Robot hmailserver |
Thu, 08 Oct 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadratic in the command's length or in the number of elements it names, and can be made to hold memory out of proportion to a command. The FETCH data-item parser normalised a BODY[] section with a case-insensitive string replacement that copied the whole item per occurrence and split the item list by repeatedly copying the remainder of the command; the server's case-insensitive search compared a needle afresh at every position, so a long SEARCH TEXT key over a message cost the product of the two lengths; SEARCH message sets and the saved-result marker ($), SORT criteria, HEADER.FIELDS name lists and UID ranges were each read once per message rather than once per command; and a FETCH naming a message's sections very many times read and held every section in memory before sending any. An IMAP command may continue past one line through non-synchronizing literals, so one command can reach about eleven megabytes. The IMAP worker threads are a small pool shared with SMTP and POP3, so a signed-in user sending such commands can make the IMAP, SMTP and POP3 services stop responding (CWE-407) and can consume excessive memory (CWE-400). | |
| Title | Inefficient Algorithmic Complexity in hMailServer | |
| Weaknesses | CWE-407 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-10-08T14:19:53.760Z
Reserved: 2026-10-08T10:52:10.640Z
Link: CVE-2026-107581
Updated: 2026-10-08T14:19:01.806Z
Status : Received
Published: 2026-10-08T12:17:16.320
Modified: 2026-10-08T15:17:44.413
Link: CVE-2026-107581
No data.
OpenCVE Enrichment
Updated: 2026-10-08T13:30:18Z