Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-47242

Опубликовано: 22 июн. 2026
Источник: debian
EPSS Низкий

Описание

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby3.3unfixedpackage
ruby3.1removedpackage
ruby2.7removedpackage

Примечания

  • https://github.com/ruby/net-imap/security/advisories/GHSA-46q3-7gv7-qmgg

EPSS

Процентиль: 3%
0.00131
Низкий

Связанные уязвимости

ubuntu
около 1 месяца назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.

nvd
около 1 месяца назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.

msrc
около 1 месяца назад

Net::IMAP: Command Injection via ID command argument

github
около 2 месяцев назад

Net::IMAP: Command Injection via ID command argument

suse-cvrf
19 дней назад

Security update for ruby3.4

EPSS

Процентиль: 3%
0.00131
Низкий