{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-107586", "assignerOrgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a", "state": "PUBLISHED", "assignerShortName": "GitLab", "dateReserved": "2026-10-08T10:52:35.638Z", "datePublished": "2026-10-08T15:11:24.474Z", "dateUpdated": "2026-10-08T15:11:24.474Z" }, "containers": { "cna": { "title": "Allocation of Resources Without Limits or Throttling in hMailServer", "descriptions": [ { "lang": "en", "value": "Uncontrolled eviction in the browser session table of the REST API in Progressive Robot hMailServer 6.2.28 through 6.3.5 allows a remote authenticated user to end other users' sessions. The table of browser sessions, shared by every account, the server administrator and support sessions, dropped its least recently used session whenever it was full, whoever it belonged to, and placed no limit on how many sessions one account could hold. A user who repeatedly signs in with their own mailbox password can therefore keep the table full and sign out every webmail and administration session that is idle for more than a short time, for as long as they continue." } ], "affected": [ { "vendor": "Progressive Robot Ltd", "product": "hMailServer", "repo": "https://gitlab.com/hmailserver/hmailserver", "versions": [ { "version": "6.2.28", "status": "affected", "lessThan": "6.3.6", "versionType": "semver" } ], "defaultStatus": "unaffected" } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "CWE-770: Allocation of Resources Without Limits or Throttling", "cweId": "CWE-770", "type": "CWE" } ] } ], "references": [ { "url": "https://gitlab.com/hmailserver/hmailserver/-/work_items/62" }, { "url": "https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "LOW", "baseScore": 4.3, "baseSeverity": "MEDIUM" } } ], "solutions": [ { "lang": "en", "value": "Upgrade to hMailServer 6.3.6, in which each account or administrator holds at most fifty sessions and gives up its own least recently used one, and a full table makes room out of the sessions of whoever holds the most. Until then: limit the rate of POST /api/v1/session per client at a reverse proxy in front of the listener, and disable an account found signing in repeatedly (its sign-ins are in the application log and its device list)." } ], "credits": [ { "lang": "en", "value": "Found in the hMailServer project's own security review (Progressive Robot Ltd)", "type": "finder" } ], "providerMetadata": { "orgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a", "shortName": "GitLab", "dateUpdated": "2026-10-08T15:11:24.474Z" } } } }