Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103649— Synchronous Access of Remote Resource without Timeout in hMailServer

Quick assessment

Affected
Progressive Robot Ltd hMailServer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: --- 在 Progressive Robot 开发的 hMailServer 6.3.0 至 6.3.5 版本的 Linux 构建中,存在缺失的网络超时机制漏洞,允许远程攻击者无限期地占用服务器线程,从而阻止出站邮件的投递(导致服务拒绝攻击)。 该服务器以 Windows 格式设置 Socket 超时,而 Linux 系统并不支持这种格式,因此未能正确启用超时设置。此外,其 HTTPS 客户端在没有设置截止时间的情况下进行读取,因此只要对端接受连接但并不发送任何数据,就可以长时间

CVSS 7.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103649

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Synchronous Access of Remote Resource without Timeout in hMailServer
Source: CVE Program / CVE List V5
Vulnerability Description
Missing network timeouts in the Linux builds of Progressive Robot hMailServer 6.3.0 through 6.3.5 allow a remote attacker to hold server threads indefinitely and so stop outbound mail delivery (denial of service). The server set its socket timeouts in the form Windows takes, which Linux refuses, and its HTTPS clients read without a deadline, so a peer that accepts a connection and then sends nothing held the waiting thread for as long as the connection stayed open. The MTA-STS policy fetch, enabled by default, is made during outbound delivery to mta-sts.<recipient domain>, so anyone who can make the server deliver mail to a domain they control - for example as the envelope sender of a message that bounces - can hold delivery threads until outbound delivery stops. The same flaw affects the DANE TLSA query, the OAuth2 token request, the ACME client, and the ManageSieve and metrics listeners, which a silent client stops from serving anyone else. Windows builds are not affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
远程资源无超时同步访问
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Progressive Robot Ltd hMailServer 6.3.0 ~ 6.3.6 -

II. Public POCs for CVE-2026-103649

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103649

请登录查看更多情报信息。

Other References for CVE-2026-103649 (2)

Same Patch Batch · Progressive Robot Ltd · 2026-10-08 · 22 CVEs total

CVE-2026-103647 8.0 HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in hM
CVE-2026-103010 7.8 HIGH Heap-based Buffer Overflow in hMailServer
CVE-2026-107573 7.8 HIGH Incorrect Default Permissions in hMailServer
CVE-2026-104658 7.8 HIGH Reliance on Untrusted Inputs in a Security Decision in hMailServer
CVE-2026-104660 7.8 HIGH Missing Authorization in hMailServer
CVE-2026-107577 7.5 HIGH Loop with Unreachable Exit Condition ('Infinite Loop') in hMailServer
CVE-2026-104659 7.5 HIGH Origin Validation Error in hMailServer
CVE-2026-107574 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107579 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107576 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107584 7.4 HIGH Not Failing Securely ('Failing Open') in hMailServer
CVE-2026-104704 7.4 HIGH Cleartext Transmission of Sensitive Information in hMailServer
CVE-2026-107578 6.7 MEDIUM Improper Link Resolution Before File Access ('Link Following') in hMailServer
CVE-2026-103011 6.5 MEDIUM Heap-based Buffer Overflow in hMailServer
CVE-2026-107572 6.5 MEDIUM Inefficient Regular Expression Complexity in hMailServer
CVE-2026-107581 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107582 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107580 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107583 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107587 5.9 MEDIUM Improper Certificate Validation in hMailServer

Showing top 20 of 22 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-103649

No comments yet


Leave a comment