Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the mail services unavailable by sending a message. Building the canonical header and choosing the header fields named in a signature's h= tag took time growing with the square of the message's header: the 'simple' canonicalisation prepended each continuation line of a folded field to the lines already gathered, and both canonicalisations searched the gathered fields from the bottom for each h= name and erased the match from the middle of the list. A message whose header holds very many fields, or a field folded over very many lines, with a DKIM-Signature the attacker signs for a domain they control, keeps a worker thread busy for tens of seconds per signature; up to ten signatures are evaluated per message by each of the DKIM and DMARC tests, on the threads that serve delivery and SMTP.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-107576 exploits inefficient algorithmic complexity in Progressive Robot hMailServer's DKIM and ARC signature verification processes. Specifically, the vulnerability stems from quadratic time complexity when building canonical headers during the 'simple' canonicalization process—each continuation line of a folded header field is prepended to previously gathered lines, causing processing time to grow with the square of the message's header size. A remote unauthenticated attacker can trivially craft a malicious email with specially formatted headers to trigger excessive CPU consumption, rendering mail services unavailable. This affects hMailServer versions 6.0.0 through 6.3.5 and impacts any organization relying on this platform for email delivery and authentication.
While this CVE lacks mapped MITRE ATT&CK techniques, Casky's Claude AI-powered analysis would detect the attack patterns underlying this vulnerability by correlating denial-of-service signatures with email protocol anomalies. Practitioners using Casky would identify suspicious patterns including: abnormally large or deeply-nested email headers, repeated header field folding/continuation patterns, and resource exhaustion metrics tied to message processing queues. The platform's extended reasoning capabilities would recognize that this represents a CWE-407 (inefficient algorithmic complexity) attack vector, surfacing findings related to protocol abuse, resource consumption anomalies, and infrastructure resilience gaps. Security teams would be prompted to implement rate limiting on header complexity, upgrade affected hMailServer instances, and monitor for emails exhibiting these malformed header characteristics.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-107576. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation