CVE-2026-42246

high
Published 2026-05-04 · Modified 2026-05-14
CVSS v3
7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v2
VIR risk
7.4

Description

net-imap vulnerable to STARTTLS stripping via invalid response timing

Predictions

Exploit likelihood
82%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-42246

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/ruby/net-imap/releases/tag/v0.5.14

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/ruby/net-imap/releases/tag/v0.4.24

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/ruby/net-imap/releases/tag/v0.3.10

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618

OS impact

OSVersionStatusFixed in
debian debianbullseyeaffected
debian debianbookwormaffected
debian debianforkyaffected
debian debiansidaffected
debian debiantrixieaffected

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsnet-imap<~> 0.3.10~> 0.3.10
ruby RubyGemsnet-imap>=0.6.0,<0.6.40.6.4
ruby RubyGemsnet-imap>=0.5.0,<0.5.140.5.14
ruby RubyGemsnet-imap>=0.4.0,<0.4.240.4.24
ruby RubyGemsnet-imap<0.3.100.3.10
ruby RUBYGEMSnet-imap>= 0, <= 0.3.90.3.10
ruby RUBYGEMSnet-imap>= 0.4.0, <= 0.4.230.4.24
ruby RUBYGEMSnet-imap>= 0.5.0, <= 0.5.130.5.14
ruby RUBYGEMSnet-imap>= 0.6.0, <= 0.6.30.6.4

Application impact

VendorProductVersionsFixed
ruby ruby-langnet\{"endExcluding":"0.3.10"}0.3.10

References

CWEs

CWE-392 CWE-393 CWE-636 CWE-754 CWE-841

Verify integrity in audit chain (admin only). AS-IS.