Hmailserver: 22 Vulnerabilities Disclosed in Single Batch, Many Causing DoS
Key findings • 22 vulnerabilities disclosed for Hmailserver on October 8, 2026, affecting versions 6.0.0 through 6.3.5. • Multiple denial-of-service vulnerabilities exist due to inefficient a…

Key findings
- 22 vulnerabilities disclosed for Hmailserver on October 8, 2026, affecting versions 6.0.0 through 6.3.5.
- Multiple denial-of-service vulnerabilities exist due to inefficient algorithmic complexity in various mail processing functions.
- High-severity flaws include local privilege escalation, unauthorized file access, and potential disruption of authentication mechanisms.
- Vulnerabilities are present in the REST API, webmail, IMAP, SMTP, POP3 services, and installer components.
- Prompt patching is essential to mitigate risks of service unavailability and unauthorized access.
On October 8, 2026, a significant batch of 22 vulnerabilities was disclosed for Hmailserver, affecting versions from 6.0.0 through 6.3.5. These vulnerabilities, disclosed within a four-hour window, range in severity from Medium to High, with many posing a significant risk of denial-of-service conditions and potential unauthorized access. The disclosures highlight several areas of concern within the email server software, including its REST API, webmail interface, and various mail processing protocols.
Several vulnerabilities stem from inefficient algorithmic complexity, leading to denial-of-service (DoS) conditions. CVE-2026-107583 and CVE-2026-107580 detail how crafted messages can overwhelm the webmail and mail services, respectively. Similarly, CVE-2026-107577 describes a MIME processing flaw that can lead to mail service unavailability, while CVE-2026-107576 points to inefficient inbound DKIM and ARC signature verification also causing DoS. CVE-2026-107574 highlights an inefficient JSON reader that can render mail services unavailable. The Sieve filter evaluation (CVE-2026-107572) and SPF macro expansion (CVE-2026-107575) also present DoS risks due to inefficient processing.
Other critical vulnerabilities impact authentication and data integrity. CVE-2026-107585 describes an uncontrolled eviction in pending sign-in tables of the REST API, potentially disrupting sign-ins for OpenID Connect, SAML, and passkey authentication. CVE-2026-107587 involves improper certificate validation in the webmail, potentially allowing an attacker to intercept S/MIME-encrypted mail. A high-severity flaw, CVE-2026-107584, relates to Hmailserver's failure to properly apply DANE for outbound SMTP delivery when DNSSEC lookups do not complete as expected. CVE-2026-104659, a high-severity vulnerability, combines missing Host header validation and inadequate throttling of failed administrator sign-ins in the REST API, enabling brute-force attacks via DNS rebinding.
Local privilege escalation and file access are also concerns. CVE-2026-107573 details incorrect default permissions in the Windows installer, allowing local authenticated users to read sensitive mail server data. A more severe local privilege escalation is described in CVE-2026-104660, where missing authorization on COM objects allows a local user to read/write arbitrary files and queue mail as any sender. On Linux systems, CVE-2026-104658 highlights a vulnerability in the live-update apply helper that runs as root, potentially allowing manipulation of update verification processes.
Further vulnerabilities include a cross-site scripting (XSS) flaw in the webmail (CVE-2026-103647), which can allow an attacker to execute scripts in the context of a user's session when they open S/MIME or OpenPGP encrypted messages. Heap-based buffer overflows were also found: CVE-2026-103011 in the legacy Blowfish encryption routine can lead to a service crash, and CVE-2026-103010 in the legacy Blowfish decryption routine on Windows allows a local user to write arbitrary bytes past a buffer boundary. Additionally, CVE-2026-107581 details inefficient IMAP command processing that can consume excessive memory, and CVE-2026-107579 describes inefficient bounce and complaint processing that can halt mail delivery. CVE-2026-103649 points to missing network timeouts in Linux builds, enabling remote attackers to hold server threads indefinitely and cause a DoS. Finally, CVE-2026-107586 involves uncontrolled eviction in the browser session table of the REST API, allowing authenticated users to terminate other users' sessions.
The affected versions range from Hmailserver 6.0.0 through 6.3.5. Users are strongly advised to update to the latest available version to mitigate these widespread security risks. The sheer number and variety of vulnerabilities disclosed simultaneously underscore the importance of prompt patching for Hmailserver installations.
Key findings from this batch of disclosures include the prevalence of denial-of-service vulnerabilities stemming from inefficient processing across multiple protocols and components. Several high-severity flaws also enable local privilege escalation and unauthorized file access, particularly on Windows systems. The REST API and webmail interfaces are recurring targets, with vulnerabilities affecting session management, authentication, and script execution. The timely patching of Hmailserver is critical to prevent widespread disruption and potential data compromise.