---
id: CVE-2026-107576
title: >-
  Inefficient algorithmic complexity in the inbound DKIM and ARC signature
  verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a
  remote unauthenticated attacker to make the mail services unavailable by
  sending a messag…
summary: >-
  Inefficient algorithmic complexity in the inbound DKIM and ARC signature
  verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a
  remote unauthenticated attacker to make the mail services unavailable by
  sending a messag…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-407
vendor: Progressive Robot Ltd
product: hMailServer
affected:
  - hMailServer >= 6.0.0 < 6.3.6
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:02:43.860'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107576'
references:
  - url: 'https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6'
    label: cve@gitlab.com
  - url: 'https://gitlab.com/hmailserver/hmailserver/-/work_items/73'
    label: cve@gitlab.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-08T14:14:51.935522Z'
ingestedAt: '2026-10-08T12:39:48.755Z'
---

## Overview

Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the mail services unavailable by sending a message. Building the canonical header and choosing the header fields named in a signature's h= tag took time growing with the square of the message's header: the 'simple' canonicalisation prepended each continuation line of a folded field to the lines already gathered, and both canonicalisations searched the gathered fields from the bottom for each h= name and erased the match from the middle of the list. A message whose header holds very many fields, or a field folded over very many lines, with a DKIM-Signature the attacker signs for a domain they control, keeps a worker thread busy for tens of seconds per signature; up to ten signatures are evaluated per message by each of the DKIM and DMARC tests, on the threads that serve delivery and SMTP.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
