CVE-2026-103011

Source
https://cve.org/CVERecord?id=CVE-2026-103011
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103011.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103011
Published
2026-10-08T10:53:15Z
Modified
2026-10-10T02:47:26Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Heap-based Buffer Overflow in hMailServer
Details

Heap-based buffer overflow in the legacy Blowfish encryption routine (BlowFishEncryptor::Encode, called by EncryptToString) in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows an authenticated mailbox user to cause a denial of service (service crash), and possibly other unspecified impact. In 6.3.4 and 6.3.5, where the self-service REST API is enabled (it is off by default), the user does this remotely by adding a fetch account whose password is 129 to 247 characters long and not a multiple of 8, and then requesting their personal data export (GET /api/v1/me/export.zip), which encrypts that password with the legacy scheme. The same flaw is reachable on Windows by any local interactive user with no hMailServer credentials, through the COM method Utilities.BlowfishEncrypt, which checked no authentication. It is also reachable by every stored-secret write when ProtectStoredSecretsWithDPAPI is set to 0. For such a length, the routine's padding loop writes up to 7 zero bytes 2 to 232 bytes past the end of its 255-byte heap buffer. The ciphertext it returns is still correct.

Database specific
{
    "cna_assigner": "GitLab",
    "cwe_ids": [
        "CWE-122"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103011.json"
}
References

Affected packages

Git / gitlab.com/hmailserver/hmailserver

Affected ranges

Type
GIT
Repo
https://gitlab.com/hmailserver/hmailserver
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "6.0.0"
        },
        {
            "fixed": "6.3.6"
        },
        {
            "fixed": "6.3.5"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

Other
build-inputs-1
v6.*
v6.0.0
v6.0.0-B3
v6.0.0-B4
v6.1.0
v6.2.0
v6.2.1
v6.2.10
v6.2.11
v6.2.12
v6.2.13
v6.2.14
v6.2.15
v6.2.16
v6.2.17
v6.2.18
v6.2.19
v6.2.2
v6.2.20
v6.2.21
v6.2.22-pre1
v6.2.22-pre2
v6.2.22-pre3
v6.2.22-pre4
v6.2.22-pre5
v6.2.22-pre6
v6.2.23-alpha1
v6.2.23-alpha2
v6.2.24
v6.2.25
v6.2.26
v6.2.27
v6.2.28
v6.2.3
v6.2.4
v6.2.5
v6.2.6
v6.2.7
v6.2.8
v6.2.9
v6.3.0
v6.3.1
v6.3.2
v6.3.3
v6.3.4
v6.3.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103011.json"