Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to hMailServer 6.3.6, which removes a MIME parameter and deletes header fields in a single pass and searches an encoded word's terminator only for a decodable word. Until then: lower the maximum message size (which bounds the quadratic paths but not the non-terminating one), and restart the service to end a hung thread.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Inefficient algorithmic complexity and a non-terminating loop in the MIME processing of received messages in Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a remote unauthenticated attacker to make the mail services unavailable by sending a message. Removing a MIME header parameter whose value is empty and directly followed by a semicolon (for example a Content-Disposition with 'filename=a.bat; filename=;') entered a loop that never terminates, holding a worker thread at full load until the server is restarted; this is reached when the attachment blocker renames a blocked attachment or a filename is set over the REST API. Separately, decoding a header field that holds many RFC 2047 encoded words of an encoding other than base64 or quoted-printable, removing a parameter with many RFC 2231 continuations, and deleting many header fields of one name each took time growing with the square of the message, on the small thread pools that serve IMAP, SMTP and POP3 connections, delivery and the REST API. | |
| Title | Loop with Unreachable Exit Condition ('Infinite Loop') in hMailServer | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-10-08T14:17:33.868Z
Reserved: 2026-10-08T10:51:50.638Z
Link: CVE-2026-107577
No data.
Status : Received
Published: 2026-10-08T12:17:15.630
Modified: 2026-10-08T12:17:15.630
Link: CVE-2026-107577
No data.
OpenCVE Enrichment
Updated: 2026-10-08T14:00:05Z