---
id: CVE-2026-103010
title: >-
  Heap-based buffer overflow in the legacy Blowfish decryption routine
  (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0
  through 6.3.3 on Windows allows a local interactive user with no hMailServer
  credentials t…
summary: >-
  Heap-based buffer overflow in the legacy Blowfish decryption routine
  (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0
  through 6.3.3 on Windows allows a local interactive user with no hMailServer
  credentials t…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-122
vendor: Progressive Robot Ltd
product: hMailServer
affected:
  - hMailServer >= 6.0.0 < 6.3.4
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:02:43.860'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103010'
references:
  - url: >-
      https://gitlab.com/hmailserver/hmailserver/-/commit/135a1908ff820ed587d5f180f98c53bd010d8931
    label: cve@gitlab.com
  - url: 'https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.4'
    label: cve@gitlab.com
  - url: 'https://gitlab.com/hmailserver/hmailserver/-/work_items/49'
    label: cve@gitlab.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-08T14:22:18.436893Z'
ingestedAt: '2026-10-08T11:31:27.687Z'
---

## Overview

Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
