Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-47242

Опубликовано: 22 июн. 2026
Источник: nvd
EPSS Низкий

Описание

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.

EPSS

Процентиль: 3%
0.00131
Низкий

Дефекты

CWE-77

Связанные уязвимости

ubuntu
около 1 месяца назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.

msrc
около 1 месяца назад

Net::IMAP: Command Injection via ID command argument

debian
около 1 месяца назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client fu ...

github
около 2 месяцев назад

Net::IMAP: Command Injection via ID command argument

suse-cvrf
19 дней назад

Security update for ruby3.4

EPSS

Процентиль: 3%
0.00131
Низкий

Дефекты

CWE-77