MODERATERubyGems →
net-imap vulnerable to command Injection via "raw" arguments to multiple commands
net-imap vulnerable to command Injection via "raw" arguments to multiple commands
Affected packages
- net-imap— 0.6.0 → 0.6.4
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/ruby/net-imap/security/advisories/GHSA-hm49-wcqc-g2xg
- https://nvd.nist.gov/vuln/detail/CVE-2026-42257
- https://github.com/ruby/net-imap/commit/0ec4fd351263e8b9a4f683713427827b7b1ad974
- https://github.com/ruby/net-imap/commit/47c72186d272441878ca73c9499f66013829ca2f
- https://github.com/ruby/net-imap/commit/6bf02aef7e0b5931010c36e377f79a71636b306b
- https://github.com/ruby/net-imap/commit/a4f7649c3da77dec7631f03a037a478eb4330048
- https://github.com/ruby/net-imap/commit/aec06996eb87a7e1bbcef1f9f8926e8add2b8c71
- https://github.com/ruby/net-imap
- https://github.com/ruby/net-imap/releases/tag/v0.4.24
- https://github.com/ruby/net-imap/releases/tag/v0.5.14
- https://github.com/ruby/net-imap/releases/tag/v0.6.4
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/net-imap/CVE-2026-42257.yml
Structured record: https://osv.dev/vulnerability/GHSA-hm49-wcqc-g2xg
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta