HIGHRubyGems →
Possible DoS by memory exhaustion in net-imap
Possible DoS by memory exhaustion in net-imap
Affected packages
- net-imap— 0.3.2 → 0.3.8
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/ruby/net-imap/security/advisories/GHSA-7fc5-f82f-cx69
- https://nvd.nist.gov/vuln/detail/CVE-2025-25186
- https://github.com/ruby/net-imap/commit/70e3ddd071a94e450b3238570af482c296380b35
- https://github.com/ruby/net-imap/commit/c8c5a643739d2669f0c9a6bb9770d0c045fd74a3
- https://github.com/ruby/net-imap/commit/cb92191b1ddce2d978d01b56a0883b6ecf0b1022
- https://github.com/ruby/net-imap
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/net-imap/CVE-2025-25186.yml
- https://ruby.github.io/net-imap/Net/IMAP/AppendUIDData.html
- https://ruby.github.io/net-imap/Net/IMAP/CopyUIDData.html
- https://ruby.github.io/net-imap/Net/IMAP/UIDPlusData.html
Structured record: https://osv.dev/vulnerability/GHSA-7fc5-f82f-cx69
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta