CVE-2026-42257

Source
https://cve.org/CVERecord?id=CVE-2026-42257
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42257.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-42257
Aliases
Downstream
Related
Published
2026-05-09T19:39:48.398Z
Modified
2026-05-28T03:54:28.864549533Z
Severity
  • 5.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
net-imap: Command Injection via "raw" arguments to multiple commands
Details

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42257.json",
    "cwe_ids": [
        "CWE-77",
        "CWE-93"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/ruby/net-imap

Affected ranges

Type
GIT
Repo
https://github.com/ruby/net-imap
Events

Affected versions

v0.*
v0.6.0
v0.6.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42257.json"