Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107586— Allocation of Resources Without Limits or Throttling in hMailServer

Quick assessment

Affected
Progressive Robot Ltd hMailServer
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Progressive Robot hMailServer 6.2.28 至 6.3.5 版本的 REST API 中,浏览器会话表存在不受控制的驱逐机制,允许经过身份验证的远程用户终止其他用户的会话。该浏览器会话表为所有账户、服务器管理员及支持会话所共享;当表已满时,系统会无条件驱逐最近最少使用的会话,而不论其归属哪个用户,且未限制单个账户可占用的会话数量上限。因此,攻击者若反复使用自己的邮箱密码登录,即可持续填满该会话表,并在其持续保持登录状态期间,导致所有空闲时间超过短阈值的 Webmail 和管理会话被

CVSS 4.3 · Medium EPSS 0.34% · P25

Affected Version Matrix 1

VendorProduct Version RangeStatus
Progressive Robot Ltd hMailServer 6.2.28< 6.3.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107586

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Allocation of Resources Without Limits or Throttling in hMailServer
Source: CVE Program / CVE List V5
Vulnerability Description
Uncontrolled eviction in the browser session table of the REST API in Progressive Robot hMailServer 6.2.28 through 6.3.5 allows a remote authenticated user to end other users' sessions. The table of browser sessions, shared by every account, the server administrator and support sessions, dropped its least recently used session whenever it was full, whoever it belonged to, and placed no limit on how many sessions one account could hold. A user who repeatedly signs in with their own mailbox password can therefore keep the table full and sign out every webmail and administration session that is idle for more than a short time, for as long as they continue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Progressive Robot Ltd hMailServer 6.2.28 ~ 6.3.6 -

II. Public POCs for CVE-2026-107586

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107586

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107586 (1)

Other References for CVE-2026-107586 (1)

Same Patch Batch · Progressive Robot Ltd · 2026-10-08 · 24 CVEs total

CVE-2026-103647 8.0 HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in hM
CVE-2026-103010 7.8 HIGH Heap-based Buffer Overflow in hMailServer
CVE-2026-107573 7.8 HIGH Incorrect Default Permissions in hMailServer
CVE-2026-104658 7.8 HIGH Reliance on Untrusted Inputs in a Security Decision in hMailServer
CVE-2026-104660 7.8 HIGH Missing Authorization in hMailServer
CVE-2026-107577 7.5 HIGH Loop with Unreachable Exit Condition ('Infinite Loop') in hMailServer
CVE-2026-107574 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107579 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107576 7.5 HIGH Inefficient Algorithmic Complexity in hMailServer
CVE-2026-103649 7.5 HIGH Synchronous Access of Remote Resource without Timeout in hMailServer
CVE-2026-104659 7.5 HIGH Origin Validation Error in hMailServer
CVE-2026-107584 7.4 HIGH Not Failing Securely ('Failing Open') in hMailServer
CVE-2026-104704 7.4 HIGH Cleartext Transmission of Sensitive Information in hMailServer
CVE-2026-107578 6.7 MEDIUM Improper Link Resolution Before File Access ('Link Following') in hMailServer
CVE-2026-107583 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-103011 6.5 MEDIUM Heap-based Buffer Overflow in hMailServer
CVE-2026-107572 6.5 MEDIUM Inefficient Regular Expression Complexity in hMailServer
CVE-2026-107581 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107582 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer
CVE-2026-107580 6.5 MEDIUM Inefficient Algorithmic Complexity in hMailServer

Showing top 20 of 24 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-107586

No comments yet


Leave a comment