Missing network timeouts in the Linux builds of Progressive Robot hMailServer 6.3.0 through 6.3.5 allow a remote attacker to hold server threads indefinitely and so stop outbound mail delivery (denial of service). The server set its socket timeouts in the form Windows takes, which Linux refuses, and its HTTPS clients read without a deadline, so a peer that accepts a connection and then sends nothing held the waiting thread for as long as the connection stayed open. The MTA-STS policy fetch, enabled by default, is made during outbound delivery to mta-sts.<recipient domain>, so anyone who can make the server deliver mail to a domain they control - for example as the envelope sender of a message that bounces - can hold delivery threads until outbound delivery stops. The same flaw affects the DANE TLSA query, the OAuth2 token request, the ACME client, and the ManageSieve and metrics listeners, which a silent client stops from serving anyone else. Windows builds are not affected.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-103649 exploits a critical oversight in Progressive Robot hMailServer versions 6.3.0 through 6.3.5 running on Linux systems. The vulnerability stems from socket timeout configuration being set in Windows-specific formats that Linux ignores, combined with HTTPS clients that read without connection deadlines. This allows remote attackers to establish connections and then send nothing, indefinitely holding server threads in a waiting state and preventing outbound mail delivery. Mail server administrators and organizations relying on hMailServer for email infrastructure are directly impacted, as attackers can trivially trigger denial of service by opening multiple idle connections.
While this CVE maps to CWE-1088 (improper initialization) rather than specific MITRE ATT&CK techniques, practitioners using Casky.ai would identify attack patterns consistent with T1499 (Service Exhaustion Denial of Service). Extended reasoning across Casky's 754 security skills enables detection of resource exhaustion signatures: sustained connections with minimal data transmission, thread pool saturation metrics, and outbound mail queue backlog anomalies. Security teams monitoring hMailServer deployments would observe unusual connection counts, threads stuck in read operations, and performance degradation patterns that Claude AI reasoning correlates with timeout bypass exploitation—triggering alerts before mail delivery completely fails.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-103649. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation