Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42257

Опубликовано: 09 мая 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.

A flaw was found in Net::IMAP, a Ruby library for Internet Message Access Protocol (IMAP) client functionality. Several Net::IMAP commands accept raw string arguments that are sent to the server without proper validation or escaping. If an application uses user-controlled input for these arguments, a remote attacker could inject Carriage Return Line Feed (CRLF) sequences.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp21/systemFix deferred
Red Hat 3scale API Management Platform 23scale-amp21/zyncFix deferred
Red Hat 3scale API Management Platform 23scale-amp22/systemFix deferred
Red Hat 3scale API Management Platform 23scale-amp22/zyncOut of support scope
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel7Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel9Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/zync-rhel8Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/zync-rhel9Out of support scope
Red Hat Enterprise Linux 10rubyFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-93
https://bugzilla.redhat.com/show_bug.cgi?id=2468494net-imap: Net::IMAP: Arbitrary IMAP command injection via CRLF sequences in unvalidated input

EPSS

Процентиль: 35%
0.00429
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.

CVSS3: 9.8
nvd
3 месяца назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.

msrc
3 месяца назад

net-imap: Command Injection via "raw" arguments to multiple commands

CVSS3: 9.8
debian
3 месяца назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client fu ...

github
3 месяца назад

net-imap vulnerable to command Injection via "raw" arguments to multiple commands

EPSS

Процентиль: 35%
0.00429
Низкий

6.1 Medium

CVSS3