Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107579— Inefficient Algorithmic Complexity in hMailServer

Quick assessment

Affected
Progressive Robot Ltd hMailServer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Progressive Robot 公司的 hMailServer 6.3.4 和 6.3.5 版本中,退信(bounce)和处理垃圾邮件投诉(complaint)的算法存在效率低下的问题。当服务器启用了退信处理或投诉处理功能(默认情况下均未启用),或管理着邮件列表时,远程未认证攻击者可通过发送特定构造的邮件阻止邮件的正常投递。 该漏洞源于 hMailServer 在处理符合 RFC 3464 的投递状态通知(DSN)或符合 RFC 5965 的滥用反馈报告(AFR)时,其内部机制在解析返回消息头部分时存在缺陷

CVSS 7.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107579

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Inefficient Algorithmic Complexity in hMailServer
Source: CVE Program / CVE List V5
Vulnerability Description
Inefficient algorithmic complexity in the bounce and complaint processing of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to stop mail delivery by sending messages, when bounce processing or complaint processing is enabled or a mailing list is managed by the server (none is by default). The readers of incoming delivery status notifications (RFC 3464) and abuse feedback reports (RFC 5965) removed the blank lines at the start of the returned headers part two bytes at a time, copying the rest of the part each time, so their work grew with the square of the number of blank lines. A message shaped like such a report, whose headers part begins with a very large number of blank lines within the reader's 2 MB limit, keeps a delivery thread busy for over a minute while it is delivered, and a few such messages a minute keep every delivery thread busy.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
算法复杂性
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Progressive Robot Ltd hMailServer 6.3.4 ~ 6.3.6 -

II. Public POCs for CVE-2026-107579

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107579

请登录查看更多情报信息。

Other References for CVE-2026-107579 (2)

Same Patch Batch · Progressive Robot Ltd · 2026-10-08 · 22 CVEs total

CVE-2026-103647 8.0 HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in hM
CVE-2026-103010 7.8 HIGH Heap-based Buffer Overflow in hMailServer
CVE-2026-104660 7.8 HIGH Missing Authorization in hMailServer
CVE-2026-104658 7.8 HIGH Reliance on Untrusted Inputs in a Security Decision in hMailServer
CVE-2026-107573 7.8 HIGH Incorrect Default Permissions in hMailServer
CVE-2026-107577 7.5 HIGH Loop with Unreachable Exit Condition ('Infinite Loop') in hMailServer
CVE-2026-107574 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107576 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-104659 7.5 HIGH Origin Validation Error in hMailServer
CVE-2026-103649 7.5 HIGH Synchronous Access of Remote Resource without Timeout in hMailServer
CVE-2026-107584 7.4 HIGH Not Failing Securely ('Failing Open') in hMailServer
CVE-2026-104704 7.4 HIGH Cleartext Transmission of Sensitive Information in hMailServer
CVE-2026-107578 6.7 MEDIUM Improper Link Resolution Before File Access ('Link Following') in hMailServer
CVE-2026-107583 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107572 6.5 MEDIUM Inefficient Regular Expression Complexity in hMailServer
CVE-2026-107581 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107582 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107580 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-103011 6.5 MEDIUM Heap-based Buffer Overflow in hMailServer
CVE-2026-107587 5.9 MEDIUM Improper Certificate Validation in hMailServer

Showing top 20 of 22 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-107579

No comments yet


Leave a comment