CVE-2026-107572
Last modified
CVE-2026-107572 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Inefficient complexity in the Sieve filter evaluation of Progressive Robot hMailServer 6.2.24 through 6.3.5 allows an authenticated account holder to make the mail services unavailable with their own filter. A ':matches' pattern was matched by a backtracking descent whose time grew with the matched value's length raised to the number of wildcards, so a pattern such as '*a*a*a*b' over 800 characters took 44 seconds; and 'deleteheader' erased the fields it removed one at a time, so removing many fields of one name over a message's header cost O(N^2) (80,000 fields took 18.8 seconds).
Description
Inefficient complexity in the Sieve filter evaluation of Progressive Robot hMailServer 6.2.24 through 6.3.5 allows an authenticated account holder to make the mail services unavailable with their own filter. A ':matches' pattern was matched by a backtracking descent whose time grew with the matched value's length raised to the number of wildcards, so a pattern such as '*a*a*a*b' over 800 characters took 44 seconds; and 'deleteheader' erased the fields it removed one at a time, so removing many fields of one name over a message's header cost O(N^2) (80,000 fields took 18.8 seconds). Sieve filters run on the small, shared delivery thread pool, so an account holder whose active script does this, fed a few messages they can send themselves, empties the pool and stops delivery for the whole server. The script is the account holder's own and cannot be set for another user.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Progressive Robot Ltd | hMailServer | >= 6.2.24, < 6.3.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-107572?
How severe is CVE-2026-107572?
How do I fix CVE-2026-107572?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107510An authenticated high privilege user can inject arguments in…9.1
- CVE-2026-10753The Site Kit by Google WordPress plugin before 1.176.0 does…2.7
- CVE-2026-10754Pega Platform versions 8.5.0 through 25.1.2 are affected by …8.6
- CVE-2026-10755The All in One SEO WordPress plugin before 4.9.9 does not c…2.7
- CVE-2026-107565A flaw was found in luksmeta. A local attacker with administ…5.1
- CVE-2026-107570heap OOB write in convert_file_from_to() via a crafted Conte…2.5
- CVE-2026-107573Incorrect default permissions in the Windows installer of Pr…7.8
- CVE-2026-107574Inefficient algorithmic complexity in the JSON reader of Pro…7.5
- CVE-2026-107575Inefficient algorithmic complexity in the SPF macro expansio…5.3
- CVE-2026-107576Inefficient algorithmic complexity in the inbound DKIM and A…7.5
- CVE-2026-107577Inefficient algorithmic complexity and a non-terminating loo…7.5
- CVE-2026-107578Improper link resolution and external control of file paths …6.7
Are you affected by CVE-2026-107572?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
