Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Alto CVE-2026-107579 Multiple Vendors

Vulnerabilidad de complejidad algorítmica en Progressive Robot hMailServer 6.3.4 y 6.3.5

Vulnerabilidad · Publicado 08/10/2026

7.5
CVSS 3.x
04 Medio7 Alto9 Crítico10
Severidad: Alto
Resumen ejecutivo

Una vulnerabilidad de complejidad algorítmica ineficiente en el procesamiento de rebotes y quejas de hMailServer permite a atacantes remotos no autenticados detener la entrega de correo mediante mensajes especialmente crafteados. El riesgo es alta cuando el procesamiento de notificaciones de estado de entrega (RFC 3464) o listas de correo están habilitadas en servidores de correo empresariales y de proveedores de servicios en LATAM.

Análisis asistido por IA, contexto LATAM revisado por el equipo 2MCI.

Descripción técnica

Descripción técnica

Inefficient algorithmic complexity in the bounce and complaint processing of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to stop mail delivery by sending messages, when bounce processing or complaint processing is enabled or a mailing list is managed by the server (none is by default). The readers of incoming delivery status notifications (RFC 3464) and abuse feedback reports (RFC 5965) removed the blank lines at the start of the returned headers part two bytes at a time, copying the rest of the part each time, so their work grew with the square of the number of blank lines. A message shaped like such a report, whose headers part begins with a very large number of blank lines within the reader's 2 MB limit, keeps a delivery thread busy for over a minute while it is delivered, and a few such messages a minute keep every delivery thread busy.

Puntuación CVSS

Score: 7.5/10 — Severidad: HIGH — Estado NIST: Received

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Debilidades (CWE)

CWE-407

Fuente oficial

Publicado en NIST NVD.

¿Qué hacer?
  • Auditar instancias hMailServer 6.3.4 y 6.3.5 en producción, especialmente servidores de correo críticos
  • Aplicar parches del fabricante inmediatamente o desactivar procesamiento de rebotes/quejas si no es esencial
  • Implementar rate limiting en puertos SMTP
  • Monitorear logs de entrega de correo para patrones anómalos
  • Consultar actualizaciones en NIST NVD y sitio oficial de Progressive Robot
Esta alerta fue generada automáticamente a partir del NVD del NIST.