CVE-2026-42258
Severity CVSS v4.0:
MEDIUM
Type:
CWE-77
Command Injection
Publication date:
09/05/2026
Last modified:
18/05/2026
Description
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.
Impact
Base Score 4.0
5.80
Severity 4.0
MEDIUM
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ruby-lang:net\:\:imap:*:*:*:*:*:ruby:*:* | 0.4.24 (excluding) | |
| cpe:2.3:a:ruby-lang:net\:\:imap:*:*:*:*:*:ruby:*:* | 0.5.0 (including) | 0.5.14 (excluding) |
| cpe:2.3:a:ruby-lang:net\:\:imap:*:*:*:*:*:ruby:*:* | 0.6.0 (including) | 0.6.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



