CVE-2026-107582
Last modified
CVE-2026-107582 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Inefficient algorithmic complexity in the REST API (6.3.3 through 6.3.5) and the IMAP PREVIEW response (6.2.22 through 6.3.5) of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. To show a snippet of each message in a folder's message list, the server decoded the character entity references of a message that has an HTML part and no text part with a string replacement whose work grew with the square of their number.
Description
Inefficient algorithmic complexity in the REST API (6.3.3 through 6.3.5) and the IMAP PREVIEW response (6.2.22 through 6.3.5) of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. To show a snippet of each message in a folder's message list, the server decoded the character entity references of a message that has an HTML part and no text part with a string replacement whose work grew with the square of their number. A received HTML-only message holding a very large number of entity references therefore keeps one of the listener's four worker threads busy for minutes or longer each time the recipient's webmail lists the folder, without the message being opened, so that a few such listings leave the HTTP listener unable to answer anybody. The IMAP PREVIEW response read such text the same way, holding an IMAP thread for each client that asks for the preview of such a message. The flaw is in the server's shared string class, whose replace and remove both ran in quadratic time.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Progressive Robot Ltd | hMailServer | >= 6.2.22-pre1, < 6.3.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-107582?
How severe is CVE-2026-107582?
How do I fix CVE-2026-107582?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107577Inefficient algorithmic complexity and a non-terminating loo…7.5
- CVE-2026-107578Improper link resolution and external control of file paths …6.7
- CVE-2026-107579Inefficient algorithmic complexity in the bounce and complai…7.5
- CVE-2026-10758Esri LERC is an open-source image or raster format which sup…7.5
- CVE-2026-107580Inefficient algorithmic complexity in the decoding of messag…6.5
- CVE-2026-107581Progressive Robot hMailServer 6.0.0 through 6.3.5 processes …6.5
- CVE-2026-107583Inefficient algorithmic complexity in the webmail's message …6.5
- CVE-2026-107584Progressive Robot hMailServer 6.0.0 through 6.3.5 fails open…7.4
- CVE-2026-107585Uncontrolled eviction in the pending sign-in tables of the R…5.3
- CVE-2026-107586Uncontrolled eviction in the browser session table of the RE…4.3
- CVE-2026-107587Improper certificate validation in the webmail of Progressiv…5.9
- CVE-2026-107589Insufficient job validation for service accounts in Jacamar …7.5
Are you affected by CVE-2026-107582?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
