PatchSiren cyber security CVE debrief
CVE-2026-107585 Progressive Robot Ltd CVE debrief
CVE-2026-107585: Allocation of Resources Without Limits or Throttling in hMailServer allows remote unauthenticated attackers to disrupt single sign-on and passkey sign-in for other users. The vulnerability affects hMailServer versions 6.3.4 and 6.3.5. Progress has released version 6.3.6 to address the issue. This vulnerability disrupts single sign-on and passkey sign-in mechanisms, potentially causing denial of service for legitimate users. Defenders should verify exposure, apply the vendor's patch, and monitor for unusual activity.
- Vendor
- Progressive Robot Ltd
- Product
- hMailServer
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for hMailServer deployments, particularly those using versions 6.3.4 or 6.3.5, should assess exposure and apply the vendor's patch. They should also review authentication and sign-in mechanisms to ensure they are properly configured and secured. Additionally, defenders should monitor for unusual sign-in activity and implement additional security measures as needed. Security teams and vulnerability management teams should prioritize验证h
Why it matters
CVE-2026-107585 is a medium-severity vulnerability in hMailServer that allows remote unauthenticated attackers to disrupt single sign-on and passkey sign-in mechanisms. Defenders should prioritize verifying exposure, applying the vendor's patch, and monitoring for unusual activity.
- Disruption of single sign-on and passkey sign-in mechanisms.
- Potential for denial of service for legitimate users.
- Need for verification of affected versions and application of patches.
- Importance of monitoring for unusual sign-in activity.
Technical summary
The vulnerability in hMailServer allows remote unauthenticated attackers to disrupt single sign-on and passkey sign-in for other users by exploiting the uncontrolled eviction in the pending sign-in tables of the REST API. This occurs because the routes that start a single sign-on and hand out a passkey sign-in challenge are reached without authentication and store pending state in bounded tables that drop their oldest entry when full. An attacker who starts sign-ins rapidly can push every other user's pending sign-in out of the table before that user's browser returns, denying single sign-on and passkey sign-in for as long as the requests continue.
Defensive priority
Defenders should prioritize verifying exposure and applying the vendor's patch.
Recommended defensive actions
- Verify if hMailServer versions 6.3.4 or 6.3.5 are in use and apply the patch to upgrade to version 6.3.6.
- Review authentication and sign-in mechanisms to ensure they are properly configured and secured.
- Monitor for unusual sign-in activity and implement additional security measures as needed.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and vendor response. The vulnerability was publicly disclosed on 2026-10-08T15:11:19.477Z. The source item provides additional context on the vulnerability and affected versions. However, the exact scope of affected deployments and potential impact on specific environments is not detailed. Defenders should verify if hMailServer versions 6.3.4 or 6.3.5 are in use and review authentication and sign-in mechanisms.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107585 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107585
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107585 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107585
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Allocation of Resources Without Limits or Throttling in hMailServer
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107585.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://gitlab.com/hmailserver/hmailserver/-/work_items/63
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.