Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to hMailServer 6.3.6, in which a pending OpenID Connect, SAML or passkey sign-in is no longer held on the server at all but carried by the browser in a cookie sealed with AES-256-GCM under a key held only in memory and good once, so there is no table a flood of unauthenticated starts can fill. Until then: limit the rate of /portal/oidc/start, /portal/saml/start and /api/v1/passkeys/challenge per client at a reverse proxy, and keep password sign-in available for administrators.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progressive Robot
Progressive Robot hmailserver |
|
| Vendors & Products |
Progressive Robot
Progressive Robot hmailserver |
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled eviction in the pending sign-in tables of the REST API in Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a remote unauthenticated attacker to make other users' OpenID Connect, SAML and passkey sign-ins fail. The routes that start a single sign-on and hand out a passkey sign-in challenge are reached without authentication and stored pending state in bounded tables that dropped their oldest entry when full, whoever had started it. An attacker who starts sign-ins a few times a second (about a hundred a second for passkeys) pushes every other user's pending sign-in out of the table before that user's browser returns, denying single sign-on and passkey sign-in for as long as the requests continue. | |
| Title | Allocation of Resources Without Limits or Throttling in hMailServer | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-10-08T19:13:35.529Z
Reserved: 2026-10-08T10:52:30.638Z
Link: CVE-2026-107585
No data.
Status : Deferred
Published: 2026-10-08T15:17:44.763
Modified: 2026-10-08T21:02:43.860
Link: CVE-2026-107585
No data.
OpenCVE Enrichment
Updated: 2026-10-08T20:00:02Z
-
CWE-770
Allocation of Resources Without Limits or Throttling