CVE-2026-107580
Last modified
CVE-2026-107580 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Inefficient algorithmic complexity in the decoding of message header fields in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the IMAP, SMTP and POP3 services, or the webmail, unavailable by sending a message. The server unfolded a decoded header value by finding each line break from the end of the value and removing it, moving the rest of the value each time, so its work grew with the square of the number of line breaks, and an RFC 2047 encoded word may decode to any number of them.
Description
Inefficient algorithmic complexity in the decoding of message header fields in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the IMAP, SMTP and POP3 services, or the webmail, unavailable by sending a message. The server unfolded a decoded header value by finding each line break from the end of the value and removing it, moving the rest of the value each time, so its work grew with the square of the number of line breaks, and an RFC 2047 encoded word may decode to any number of them. A received message whose Subject or other header field holds such a value keeps a worker thread busy for minutes or longer each time the value is read: when the recipient's IMAP client searches, sorts or threads the folder by a header, when the webmail lists the folder, and, where configured, when a rule tests a header, a spam tag is added to the Subject or an abuse report is read during delivery. The IMAP worker threads are shared with SMTP and POP3, so a few such messages stop those services responding. The server's reading of a message header from its file also searched everything read so far after each 4,000 bytes, costing seconds for a header of tens of megabytes.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Progressive Robot Ltd | hMailServer | >= 6.0.0, < 6.3.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-107580?
How severe is CVE-2026-107580?
How do I fix CVE-2026-107580?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107575Inefficient algorithmic complexity in the SPF macro expansio…5.3
- CVE-2026-107576Inefficient algorithmic complexity in the inbound DKIM and A…7.5
- CVE-2026-107577Inefficient algorithmic complexity and a non-terminating loo…7.5
- CVE-2026-107578Improper link resolution and external control of file paths …6.7
- CVE-2026-107579Inefficient algorithmic complexity in the bounce and complai…7.5
- CVE-2026-10758Esri LERC is an open-source image or raster format which sup…7.5
- CVE-2026-107581Progressive Robot hMailServer 6.0.0 through 6.3.5 processes …6.5
- CVE-2026-107582Inefficient algorithmic complexity in the REST API (6.3.3 th…6.5
- CVE-2026-107583Inefficient algorithmic complexity in the webmail's message …6.5
- CVE-2026-107584Progressive Robot hMailServer 6.0.0 through 6.3.5 fails open…7.4
- CVE-2026-107585Uncontrolled eviction in the pending sign-in tables of the R…5.3
- CVE-2026-107586Uncontrolled eviction in the browser session table of the RE…4.3
Are you affected by CVE-2026-107580?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
