PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107575 Progressive Robot Ltd CVE debrief

A vulnerability in hMailServer allows remote attackers to cause a denial of service by publishing a crafted SPF record that consumes worker-thread time. The issue arises from inefficient algorithmic complexity in the SPF macro expansion of hMailServer 6.3.4 and 6.3.5. An attacker can publish a crafted SPF record to consume worker-thread time, leading to a denial of service. System administrators and security teams should assess exposure and update to version 6.3.6 or later. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM.

Vendor
Progressive Robot Ltd
Product
hMailServer
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

System administrators and security teams responsible for hMailServer installations should assess exposure and update to version 6.3.6 or later. They should also monitor SPF record publications for potential abuse and implement rate limiting on SPF checks. Additionally, they should review and update their systems to ensure they are not vulnerable to this issue.

Why it matters

CVE-2026-107575 allows remote attackers to cause a denial of service in hMailServer by publishing a crafted SPF record. System administrators and security teams should assess exposure, update to version 6.3.6 or later, and monitor SPF record publications.

  • Denial of service through worker-thread time consumption
  • Potential for partial loss of availability
  • Need for verification of affected versions and remediation
  • Importance of monitoring SPF record publications

Technical summary

The vulnerability is caused by inefficient algorithmic complexity in the SPF macro expansion of hMailServer 6.3.4 and 6.3.5. An attacker can publish a crafted SPF record to consume worker-thread time, leading to a denial of service. The expansion is bounded by SPF's own per-term and per-macro limits, so the loss of availability is partial. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The affected product is hMailServer, and the vulnerability affects versions 6.3.4 and 6.3.5. The recommended solution is to update to version 6.3.6 or later.

Defensive priority

Medium

Recommended defensive actions

  • Review and update hMailServer to version 6.3.6 or later
  • Monitor SPF record publications for potential abuse
  • Implement rate limiting on SPF checks
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the vulnerability, but limited information is available on potential exploits or victims. The vulnerability affects hMailServer versions 6.3.4 and 6.3.5. There is no information on publicly available exploits or reports of attacks. The CVE record was published on 2026-10-08T11:46:46.082Z and has not been modified since then. The source item provides additional details on the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107575 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107575

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107575 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107575

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Inefficient Algorithmic Complexity in hMailServer

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107575.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://gitlab.com/hmailserver/hmailserver/-/work_items/74

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.