Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-42258

27
FAUCET Score

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.

First published: May 9, 2026Last modified: May 11, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 0.4.24CPE matchmatch criteria
cpe:2.3:a:ruby-lang:net\:\:imap:*:*:*:*:*:ruby:*:*
>= 0.5.0, < 0.5.14CPE matchmatch criteria
cpe:2.3:a:ruby-lang:net\:\:imap:*:*:*:*:*:ruby:*:*
>= 0.6.0, < 0.6.4CPE matchmatch criteria
cpe:2.3:a:ruby-lang:net\:\:imap:*:*:*:*:*:ruby:*:*

CVSS Data

CVSS version used by this source: 4.0

5.8MEDIUM

CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.78%
Probability of exploitation in next 30 days
EPSS Percentile
52.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0078 is in the 33rd percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

rubygemspatch availablevia ghsa
Product: net-imapFixed in: 0.6.4
rubygemspatch availablevia ghsa
Product: net-imapFixed in: 0.5.14
rubygemspatch availablevia ghsa
Product: net-imapFixed in: 0.4.24
ubuntupatch availablevia ubuntu_usn
Product: ruby2.3 (xenial)Fixed in: 2.3.1-2~ubuntu16.04.16+esm15
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (3)

ubuntuUSN-8556-1

Ruby vulnerabilities

Jul 16, 2026
microsoft2026-May/CVE-2026-42258Moderate

net-imap: Command Injection via unvalidated Symbol inputs

May 7, 2026
rubygemsGHSA-75xq-5h9v-w6pxmedium

net-imap vulnerable to command Injection via unvalidated Symbol inputs

May 4, 2026

References

access.redhat.com / errata/RHSA-2026:33462
access.redhat.com / errata/RHSA-2026:33512
access.redhat.com / errata/RHSA-2026:33514
access.redhat.com / errata/RHSA-2026:33515
access.redhat.com / errata/RHSA-2026:33540
access.redhat.com / errata/RHSA-2026:33565
access.redhat.com / errata/RHSA-2026:33576
access.redhat.com / errata/RHSA-2026:33577
access.redhat.com / errata/RHSA-2026:33630
access.redhat.com / errata/RHSA-2026:34076
access.redhat.com / errata/RHSA-2026:35834
access.redhat.com / errata/RHSA-2026:35866
access.redhat.com / errata/RHSA-2026:35867
access.redhat.com / errata/RHSA-2026:35895
access.redhat.com / errata/RHSA-2026:36099
access.redhat.com / errata/RHSA-2026:36978
access.redhat.com / errata/RHSA-2026:37238
access.redhat.com / errata/RHSA-2026:37397
access.redhat.com / errata/RHSA-2026:38694
access.redhat.com / errata/RHSA-2026:40380
access.redhat.com / security/cve/CVE-2026-42258
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-42258.json
github.com / ruby/net-imap/releases/tag/v0.4.24
Release Notes
github.com / ruby/net-imap/releases/tag/v0.5.14
Release Notes
github.com / ruby/net-imap/releases/tag/v0.6.4
Release Notes
github.com / ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px
MitigationVendor Advisory