Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade to hMailServer 6.3.6, in which each account or administrator holds at most fifty sessions and gives up its own least recently used one, and a full table makes room out of the sessions of whoever holds the most. Until then: limit the rate of POST /api/v1/session per client at a reverse proxy in front of the listener, and disable an account found signing in repeatedly (its sign-ins are in the application log and its device list).
Workaround
No workaround given by the vendor.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled eviction in the browser session table of the REST API in Progressive Robot hMailServer 6.2.28 through 6.3.5 allows a remote authenticated user to end other users' sessions. The table of browser sessions, shared by every account, the server administrator and support sessions, dropped its least recently used session whenever it was full, whoever it belonged to, and placed no limit on how many sessions one account could hold. A user who repeatedly signs in with their own mailbox password can therefore keep the table full and sign out every webmail and administration session that is idle for more than a short time, for as long as they continue. | |
| Title | Allocation of Resources Without Limits or Throttling in hMailServer | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-10-08T19:12:52.460Z
Reserved: 2026-10-08T10:52:35.638Z
Link: CVE-2026-107586
No data.
Status : Deferred
Published: 2026-10-08T15:17:44.897
Modified: 2026-10-08T21:02:43.860
Link: CVE-2026-107586
No data.
OpenCVE Enrichment
Updated: 2026-10-08T17:30:17Z