{"api_version":"1","generated_at":"2026-10-08T14:57:16+00:00","cve":"CVE-2026-107583","urls":{"html":"https://cve.report/CVE-2026-107583","api":"https://cve.report/api/cve/CVE-2026-107583.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-107583","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-107583"},"summary":{"title":"Inefficient Algorithmic Complexity in hMailServer","description":"Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. The route that renders a received message's HTML replaced each reference to an embedded image in place, with work that grew with the square of the number of references, and wrote the image out for every reference while counting it against its size limit only once. A message whose HTML refers to one small embedded image a very large number of times, opened in the webmail by its recipient, therefore keeps one of the listener's four worker threads busy for minutes and makes it build a document of gigabytes, so that a few such messages leave the HTTP listener unable to answer anybody.","state":"PUBLISHED","assigner":"GitLab","published_at":"2026-10-08 12:17:16","updated_at":"2026-10-08 12:17:16"},"problem_types":["CWE-407","CWE-407 CWE-407: Inefficient Algorithmic Complexity"],"metrics":[{"version":"3.1","source":"cve@gitlab.com","type":"Secondary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","name":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","refsource":"cve@gitlab.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/65","name":"https://gitlab.com/hmailserver/hmailserver/-/work_items/65","refsource":"cve@gitlab.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-107583","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107583","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Progressive Robot Ltd","product":"hMailServer","version":"affected 6.3.2 6.3.6 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade to hMailServer 6.3.6, in which the route reads a message's HTML once to find the images it names and once to write them, and writes at most 24 MB of inlined images in all, every reference counted. Until then: lower the maximum message size, which bounds the cost (it grows with the square of the HTML's size); leave the webmail's offline store off so that only an opened message triggers it; or keep the REST listener off (RestApiPort 0, the default).","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Found in the hMailServer project's own security review (Progressive Robot Ltd)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"hMailServer","repo":"https://gitlab.com/hmailserver/hmailserver","vendor":"Progressive Robot Ltd","versions":[{"lessThan":"6.3.6","status":"affected","version":"6.3.2","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Found in the hMailServer project's own security review (Progressive Robot Ltd)"}],"descriptions":[{"lang":"en","value":"Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. The route that renders a received message's HTML replaced each reference to an embedded image in place, with work that grew with the square of the number of references, and wrote the image out for every reference while counting it against its size limit only once. A message whose HTML refers to one small embedded image a very large number of times, opened in the webmail by its recipient, therefore keeps one of the listener's four worker threads busy for minutes and makes it build a document of gigabytes, so that a few such messages leave the HTTP listener unable to answer anybody."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-407","description":"CWE-407: Inefficient Algorithmic Complexity","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-08T11:49:06.081Z","orgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","shortName":"GitLab"},"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/65"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6"}],"solutions":[{"lang":"en","value":"Upgrade to hMailServer 6.3.6, in which the route reads a message's HTML once to find the images it names and once to write them, and writes at most 24 MB of inlined images in all, every reference counted. Until then: lower the maximum message size, which bounds the cost (it grows with the square of the HTML's size); leave the webmail's offline store off so that only an opened message triggers it; or keep the REST listener off (RestApiPort 0, the default)."}],"title":"Inefficient Algorithmic Complexity in hMailServer"}},"cveMetadata":{"assignerOrgId":"ceab7361-8a18-47b1-92ba-4d7d25f6715a","assignerShortName":"GitLab","cveId":"CVE-2026-107583","datePublished":"2026-10-08T11:49:06.081Z","dateReserved":"2026-10-08T10:52:20.637Z","dateUpdated":"2026-10-08T11:49:06.081Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-08 12:17:16","lastModifiedDate":"2026-10-08 12:17:16","problem_types":["CWE-407","CWE-407 CWE-407: Inefficient Algorithmic Complexity"],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"107583","Ordinal":"1","Title":"Inefficient Algorithmic Complexity in hMailServer","CVE":"CVE-2026-107583","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"107583","Ordinal":"1","NoteData":"Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API unavailable by sending a message. The route that renders a received message's HTML replaced each reference to an embedded image in place, with work that grew with the square of the number of references, and wrote the image out for every reference while counting it against its size limit only once. A message whose HTML refers to one small embedded image a very large number of times, opened in the webmail by its recipient, therefore keeps one of the listener's four worker threads busy for minutes and makes it build a document of gigabytes, so that a few such messages leave the HTTP listener unable to answer anybody.","Type":"Description","Title":"Inefficient Algorithmic Complexity in hMailServer"}]}}}