{"id":"CVE-2026-107585","summary":"Allocation of Resources Without Limits or Throttling in hMailServer","details":"Uncontrolled eviction in the pending sign-in tables of the REST API in Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to make other users' OpenID Connect, SAML and passkey sign-ins fail. The routes that start a single sign-on and hand out a passkey sign-in challenge are reached without authentication and stored pending state in bounded tables that dropped their oldest entry when full, whoever had started it. An attacker who starts sign-ins a few times a second (about a hundred a second for passkeys) pushes every other user's pending sign-in out of the table before that user's browser returns, denying single sign-on and passkey sign-in for as long as the requests continue.","modified":"2026-10-10T02:47:23.306757016Z","published":"2026-10-08T15:11:19.477Z","database_specific":{"cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107585.json","cna_assigner":"GitLab"},"references":[{"type":"WEB","url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6"},{"type":"WEB","url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/63"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107585.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107585"},{"type":"PACKAGE","url":"https://gitlab.com/hmailserver/hmailserver"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/hmailserver/hmailserver","events":[{"introduced":"51e2dbda08d6aa7fcda5a48f1af05221809f78be"},{"fixed":"e3c448aa66fc310b74d076884d54fae951296915"}],"database_specific":{"extracted_events":[{"introduced":"6.3.4"},{"fixed":"6.3.6"}],"source":"AFFECTED_FIELD"}}],"versions":["v6.3.5","v6.3.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107585.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}