Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the mail services unavailable. Reading a JSON object kept the first of each duplicated member name by searching the members already read, so an object of N distinct member names cost O(N^2): 1 MB took 8.9 seconds and 4 MB took 300 seconds against the affected code. A remote attacker reaches the reader without an account by mailing a crafted TLS-RPT report (up to 16 MB after decompression) to a hosted domain's published report mailbox, which is read on a delivery thread; a few such reports hold every delivery thread (ten by default), so the server delivers no mail, local or outbound, for over an hour per report. A signed-in account reaches the same 16 MB body through the webmail's own REST routes, holding the REST API's own worker threads. Where no report mailbox is configured, the unauthenticated REST sign-in routes that read a JSON body are capped at
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-107574 exploits inefficient algorithmic complexity in hMailServer's JSON reader, enabling remote unauthenticated attackers to render mail services unavailable. The vulnerability stems from a O(N²) algorithm that searches previously-read member names when processing duplicate JSON keys, causing severe performance degradation—processing just 4 MB of malicious JSON consumes approximately 5 minutes of CPU time. Attackers bypass authentication entirely by embedding crafted payloads in TLS-RPT (TLS Reporting Protocol) reports, which mail servers process automatically. This affects any organization running vulnerable hMailServer instances, particularly those relying on automated security reporting mechanisms, as the attack requires no credentials and leverages legitimate protocol channels.
While this CVE lacks direct MITRE ATT&CK technique mappings, Casky's Claude-powered platform detects the attack patterns through resource exhaustion monitoring and protocol anomaly analysis. Practitioners using Casky would observe: (1) sudden CPU spikes correlated with TLS-RPT message processing, (2) JSON parsing operations consuming disproportionate computational resources relative to payload size, and (3) mail service unavailability without typical error logs indicating crashes or authentication failures. By correlating algorithmic behavior patterns with CWE-407 (Inefficient Algorithmic Complexity), Casky surfaces this as a Denial of Service attack vector that eludes traditional signature-based detection. Extended reasoning enables practitioners to identify the root cause as algorithmic weakness rather than resource misconfiguration, guiding remediation toward parser optimization or input validation controls.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-107574. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation