Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107575— Inefficient Algorithmic Complexity in hMailServer

Quick assessment

Affected
Progressive Robot Ltd hMailServer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Progressive Robot hMailServer 6.3.4 和 6.3.5 版本中,SPF 宏展开过程存在低效的算法复杂度,使得远程未认证攻击者可以通过发布精心构造的 SPF 记录,消耗工作线程的时间资源。根据 RFC 7208 第 7.1 节的要求,当待查询的域名过长时,应从左侧开始逐步丢弃整个标签(label);而该服务器在实现时,每次仅移除一个标签,并重新复制剩余的域名字符串,导致计算工作量随宏展开长度呈平方级增长。攻击者若控制某个域名,并发布一条 SPF 记录,其机制中的域名规范(domain-

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 1

VendorProduct Version RangeStatus
Progressive Robot Ltd hMailServer 6.3.4< 6.3.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107575

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Inefficient Algorithmic Complexity in hMailServer
Source: CVE Program / CVE List V5
Vulnerability Description
Inefficient algorithmic complexity in the SPF macro expansion of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to consume worker-thread time by publishing a crafted SPF record. RFC 7208 section 7.1 requires a name too long to look up to lose whole labels from the left; the server did this by removing one label at a time and copying the rest of the name each time, so the work grew with the square of the expansion. An attacker who publishes an SPF record for a domain they control, with a mechanism whose domain-spec expands through macros to a name far longer than 253 characters, makes the SPF check of a message from that domain take several seconds. The expansion is bounded by SPF's own per-term and per-macro limits, so the loss of availability is partial.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
算法复杂性
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Progressive Robot Ltd hMailServer 6.3.4 ~ 6.3.6 -

II. Public POCs for CVE-2026-107575

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107575

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107575 (1)

Vendor Advisories for CVE-2026-107575 (1)

Same Patch Batch · Progressive Robot Ltd · 2026-10-08 · 24 CVEs total

CVE-2026-103647 8.0 HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in hM
CVE-2026-103010 7.8 HIGH Heap-based Buffer Overflow in hMailServer
CVE-2026-107573 7.8 HIGH Incorrect Default Permissions in hMailServer
CVE-2026-104658 7.8 HIGH Reliance on Untrusted Inputs in a Security Decision in hMailServer
CVE-2026-104660 7.8 HIGH Missing Authorization in hMailServer
CVE-2026-104659 7.5 HIGH Origin Validation Error in hMailServer
CVE-2026-103649 7.5 HIGH Synchronous Access of Remote Resource without Timeout in hMailServer
CVE-2026-107577 7.5 HIGH Loop with Unreachable Exit Condition ('Infinite Loop') in hMailServer
CVE-2026-107574 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107579 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107576 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-104704 7.4 HIGH Cleartext Transmission of Sensitive Information in hMailServer
CVE-2026-107584 7.4 HIGH Not Failing Securely ('Failing Open') in hMailServer
CVE-2026-107578 6.7 MEDIUM Improper Link Resolution Before File Access ('Link Following') in hMailServer
CVE-2026-107572 6.5 MEDIUM Inefficient Regular Expression Complexity in hMailServer
CVE-2026-107580 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107582 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107581 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-103011 6.5 MEDIUM Heap-based Buffer Overflow in hMailServer
CVE-2026-107583 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer

Showing top 20 of 24 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-107575

No comments yet


Leave a comment