Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-42245

Опубликовано: 09 мая 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client's CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.

РелизСтатусПримечание
devel

needs-triage

esm-apps-legacy/xenial

not-affected

no ResponseReader/SCRAM class in bundled net/imap.rb
esm-apps/bionic

not-affected

no ResponseReader/SCRAM class in bundled net/imap.rb
esm-apps/focal

not-affected

no ResponseReader/SCRAM class in bundled net/imap.rb
esm-apps/noble

not-affected

no ResponseReader/SCRAM class in bundled net/imap.rb
esm-apps/resolute

not-affected

no ResponseReader/SCRAM class in bundled net/imap.rb
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

not-affected

no ResponseReader/SCRAM class in bundled net/imap.rb
jammy

DNE

noble

not-affected

no ResponseReader/SCRAM class in bundled net/imap.rb

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/xenial

not-affected

no ResponseReader class in monolithic imap.rb
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

no ResponseReader class; uses line-by-line get_response

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

not-affected

ruby2.5 stdlib uses per-line response reading; no ResponseReader class
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

not-affected

no ResponseReader class in monolithic imap.rb
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

no ResponseReader class; uses line-by-line get_response

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

not-affected

no ResponseReader class in monolithic imap.rb
noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

no ResponseReader class; uses line-by-line get_response

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

DNE

noble

not-affected

no ResponseReader class; net-imap 0.3.4.1 predates ResponseReader
questing

DNE

resolute

DNE

upstream

not-affected

no ResponseReader class; net-imap 0.3.4.1 predates ResponseReader

Показывать по

РелизСтатусПримечание
devel

needs-triage

jammy

DNE

noble

DNE

questing

ignored

end of standard support
resolute

not-affected

no ResponseReader class in net-imap 0.4.19
upstream

not-affected

no ResponseReader class in net-imap 0.4.19

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
3 месяца назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client's CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.

CVSS3: 7.5
nvd
3 месяца назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client's CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.

CVSS3: 7.5
debian
3 месяца назад

Net::IMAP implements Internet Message Access Protocol (IMAP) client fu ...

github
3 месяца назад

net-imap has quadratic complexity when reading response literals

rocky
около 1 месяца назад

Important: ruby:4.0 security update

7.5 High

CVSS3