PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107585 Progressive Robot Ltd CVE debrief

CVE-2026-107585: Allocation of Resources Without Limits or Throttling in hMailServer allows remote unauthenticated attackers to disrupt single sign-on and passkey sign-in for other users. The vulnerability affects hMailServer versions 6.3.4 and 6.3.5. Progress has released version 6.3.6 to address the issue. This vulnerability disrupts single sign-on and passkey sign-in mechanisms, potentially causing denial of service for legitimate users. Defenders should verify exposure, apply the vendor's patch, and monitor for unusual activity.

Vendor
Progressive Robot Ltd
Product
hMailServer
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for hMailServer deployments, particularly those using versions 6.3.4 or 6.3.5, should assess exposure and apply the vendor's patch. They should also review authentication and sign-in mechanisms to ensure they are properly configured and secured. Additionally, defenders should monitor for unusual sign-in activity and implement additional security measures as needed. Security teams and vulnerability management teams should prioritize验证h

Why it matters

CVE-2026-107585 is a medium-severity vulnerability in hMailServer that allows remote unauthenticated attackers to disrupt single sign-on and passkey sign-in mechanisms. Defenders should prioritize verifying exposure, applying the vendor's patch, and monitoring for unusual activity.

  • Disruption of single sign-on and passkey sign-in mechanisms.
  • Potential for denial of service for legitimate users.
  • Need for verification of affected versions and application of patches.
  • Importance of monitoring for unusual sign-in activity.

Technical summary

The vulnerability in hMailServer allows remote unauthenticated attackers to disrupt single sign-on and passkey sign-in for other users by exploiting the uncontrolled eviction in the pending sign-in tables of the REST API. This occurs because the routes that start a single sign-on and hand out a passkey sign-in challenge are reached without authentication and store pending state in bounded tables that drop their oldest entry when full. An attacker who starts sign-ins rapidly can push every other user's pending sign-in out of the table before that user's browser returns, denying single sign-on and passkey sign-in for as long as the requests continue.

Defensive priority

Defenders should prioritize verifying exposure and applying the vendor's patch.

Recommended defensive actions

  • Verify if hMailServer versions 6.3.4 or 6.3.5 are in use and apply the patch to upgrade to version 6.3.6.
  • Review authentication and sign-in mechanisms to ensure they are properly configured and secured.
  • Monitor for unusual sign-in activity and implement additional security measures as needed.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and vendor response. The vulnerability was publicly disclosed on 2026-10-08T15:11:19.477Z. The source item provides additional context on the vulnerability and affected versions. However, the exact scope of affected deployments and potential impact on specific environments is not detailed. Defenders should verify if hMailServer versions 6.3.4 or 6.3.5 are in use and review authentication and sign-in mechanisms.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107585 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107585

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107585 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107585

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.