Progressive Robot hMailServer 6.3.4 和 6.3.5 版本中,SPF 宏展开过程存在低效的算法复杂度,使得远程未认证攻击者可以通过发布精心构造的 SPF 记录,消耗工作线程的时间资源。根据 RFC 7208 第 7.1 节的要求,当待查询的域名过长时,应从左侧开始逐步丢弃整个标签(label);而该服务器在实现时,每次仅移除一个标签,并重新复制剩余的域名字符串,导致计算工作量随宏展开长度呈平方级增长。攻击者若控制某个域名,并发布一条 SPF 记录,其机制中的域名规范(domain-
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progressive Robot Ltd | hMailServer | 6.3.4< 6.3.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progressive Robot Ltd | hMailServer | 6.3.4 ~ 6.3.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103647 | 8.0 HIGH | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in hM |
| CVE-2026-103010 | 7.8 HIGH | Heap-based Buffer Overflow in hMailServer |
| CVE-2026-107573 | 7.8 HIGH | Incorrect Default Permissions in hMailServer |
| CVE-2026-104658 | 7.8 HIGH | Reliance on Untrusted Inputs in a Security Decision in hMailServer |
| CVE-2026-104660 | 7.8 HIGH | Missing Authorization in hMailServer |
| CVE-2026-104659 | 7.5 HIGH | Origin Validation Error in hMailServer |
| CVE-2026-103649 | 7.5 HIGH | Synchronous Access of Remote Resource without Timeout in hMailServer |
| CVE-2026-107577 | 7.5 HIGH | Loop with Unreachable Exit Condition ('Infinite Loop') in hMailServer |
| CVE-2026-107574 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107579 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107576 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-104704 | 7.4 HIGH | Cleartext Transmission of Sensitive Information in hMailServer |
| CVE-2026-107584 | 7.4 HIGH | Not Failing Securely ('Failing Open') in hMailServer |
| CVE-2026-107578 | 6.7 MEDIUM | Improper Link Resolution Before File Access ('Link Following') in hMailServer |
| CVE-2026-107572 | 6.5 MEDIUM | Inefficient Regular Expression Complexity in hMailServer |
| CVE-2026-107580 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107582 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107581 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-103011 | 6.5 MEDIUM | Heap-based Buffer Overflow in hMailServer |
| CVE-2026-107583 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet