CVE-2026-42257

critical
Published 2026-05-04 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
9.8

Description

net-imap vulnerable to command Injection via "raw" arguments to multiple commands

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-42257

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/ruby/net-imap/security/advisories/GHSA-hm49-wcqc-g2xg

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/ruby/net-imap/releases/tag/v0.6.4

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/ruby/net-imap/releases/tag/v0.5.14

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/ruby/net-imap/releases/tag/v0.4.24

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianforkyaffected
debian debiansidaffected
debian debiantrixieaffected
debian debianbullseyeaffected

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsnet-imap<~> 0.4.24~> 0.4.24
ruby RubyGemsnet-imap>=0.6.0,<0.6.40.6.4
ruby RubyGemsnet-imap>=0.5.0,<0.5.140.5.14
ruby RubyGemsnet-imap<0.4.240.4.24
ruby RUBYGEMSnet-imap>= 0, <= 0.4.230.4.24
ruby RUBYGEMSnet-imap>= 0.5.0, <= 0.5.130.5.14
ruby RUBYGEMSnet-imap>= 0.6.0, <= 0.6.30.6.4

Application impact

VendorProductVersionsFixed
ruby-langnet\{"endExcluding":"0.4.24"}0.4.24

References

CWEs

CWE-77 CWE-93

Verify integrity in audit chain (admin only). AS-IS.