๐Ÿ” CVE Alert

CVE-2026-107575

MEDIUM 5.3

Inefficient Algorithmic Complexity in hMailServer

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Inefficient algorithmic complexity in the SPF macro expansion of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to consume worker-thread time by publishing a crafted SPF record. RFC 7208 section 7.1 requires a name too long to look up to lose whole labels from the left; the server did this by removing one label at a time and copying the rest of the name each time, so the work grew with the square of the expansion. An attacker who publishes an SPF record for a domain they control, with a mechanism whose domain-spec expands through macros to a name far longer than 253 characters, makes the SPF check of a message from that domain take several seconds. The expansion is bounded by SPF's own per-term and per-macro limits, so the loss of availability is partial.

CWE CWE-407
Vendor progressive robot ltd
Product hmailserver
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for progressive robot ltd hmailserver

Be the first to know when new medium vulnerabilities affecting progressive robot ltd hmailserver are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

Progressive Robot Ltd / hMailServer
6.3.4 < 6.3.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gitlab.com: https://gitlab.com/hmailserver/hmailserver/-/work_items/74 gitlab.com: https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6

Credits

Found in the hMailServer project's own security review (Progressive Robot Ltd)