CVE-2026-107574
Last modified
CVE-2026-107574 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the mail services unavailable. Reading a JSON object kept the first of each duplicated member name by searching the members already read, so an object of N distinct member names cost O(N^2): 1 MB took 8.9 seconds and 4 MB took 300 seconds against the affected code.
Description
Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the mail services unavailable. Reading a JSON object kept the first of each duplicated member name by searching the members already read, so an object of N distinct member names cost O(N^2): 1 MB took 8.9 seconds and 4 MB took 300 seconds against the affected code. A remote attacker reaches the reader without an account by mailing a crafted TLS-RPT report (up to 16 MB after decompression) to a hosted domain's published report mailbox, which is read on a delivery thread; a few such reports hold every delivery thread (ten by default), so the server delivers no mail, local or outbound, for over an hour per report. A signed-in account reaches the same 16 MB body through the webmail's own REST routes, holding the REST API's own worker threads. Where no report mailbox is configured, the unauthenticated REST sign-in routes that read a JSON body are capped at 64 KB and are not affected.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Progressive Robot Ltd | hMailServer | >= 6.2.28, < 6.3.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-107574?
How severe is CVE-2026-107574?
How do I fix CVE-2026-107574?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10754Pega Platform versions 8.5.0 through 25.1.2 are affected by …8.6
- CVE-2026-10755The All in One SEO WordPress plugin before 4.9.9 does not c…2.7
- CVE-2026-107565A flaw was found in luksmeta. A local attacker with administ…5.1
- CVE-2026-107570heap OOB write in convert_file_from_to() via a crafted Conte…2.5
- CVE-2026-107572Inefficient complexity in the Sieve filter evaluation of Pro…6.5
- CVE-2026-107573Incorrect default permissions in the Windows installer of Pr…7.8
- CVE-2026-107575Inefficient algorithmic complexity in the SPF macro expansio…5.3
- CVE-2026-107576Inefficient algorithmic complexity in the inbound DKIM and A…7.5
- CVE-2026-107577Inefficient algorithmic complexity and a non-terminating loo…7.5
- CVE-2026-107578Improper link resolution and external control of file paths …6.7
- CVE-2026-107579Inefficient algorithmic complexity in the bounce and complai…7.5
- CVE-2026-10758Esri LERC is an open-source image or raster format which sup…7.5
Are you affected by CVE-2026-107574?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
