{"id":"CVE-2026-107572","summary":"Inefficient Regular Expression Complexity in hMailServer","details":"Inefficient complexity in the Sieve filter evaluation of Progressive Robot hMailServer 6.2.24 through 6.3.5 allows an authenticated account holder to make the mail services unavailable with their own filter. A ':matches' pattern was matched by a backtracking descent whose time grew with the matched value's length raised to the number of wildcards, so a pattern such as '*a*a*a*b' over 800 characters took 44 seconds; and 'deleteheader' erased the fields it removed one at a time, so removing many fields of one name over a message's header cost O(N^2) (80,000 fields took 18.8 seconds). Sieve filters run on the small, shared delivery thread pool, so an account holder whose active script does this, fed a few messages they can send themselves, empties the pool and stops delivery for the whole server. The script is the account holder's own and cannot be set for another user.","modified":"2026-10-10T02:47:27.727785245Z","published":"2026-10-08T11:46:41.080Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107572.json","cna_assigner":"GitLab","cwe_ids":["CWE-1333"]},"references":[{"type":"WEB","url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6"},{"type":"WEB","url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/75"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107572.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107572"},{"type":"PACKAGE","url":"https://gitlab.com/hmailserver/hmailserver"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/hmailserver/hmailserver","events":[{"introduced":"0d9a77a6e84de73bb4dd64e392b10016732cb6d5"},{"fixed":"e3c448aa66fc310b74d076884d54fae951296915"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"6.2.24"},{"fixed":"6.3.6"},{"fixed":"6.3.5"}]}}],"versions":["v6.3.5","v6.3.4","v6.3.3","v6.3.2","build-inputs-1","v6.3.1","v6.3.0","v6.2.28","v6.2.27","v6.2.26","v6.2.25","v6.2.24"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107572.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}