CVE-2026-42258: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') in ruby net-imap
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.
AI Analysis
Technical Summary
The Ruby net-imap library, which implements IMAP client functionality, contains a command injection vulnerability (CWE-77 and CWE-93) in versions prior to 0.4.24, 0.5.14, and 0.6.4. This vulnerability arises from improper neutralization of special elements in symbol arguments passed to IMAP commands, enabling injection of arbitrary IMAP commands. Exploitation could allow an attacker to perform unauthorized IMAP operations, impacting confidentiality and integrity of email data. Red Hat advisories confirm the issue and provide patched versions. The vulnerability does not permit arbitrary code execution and is limited to email system impacts.
Potential Impact
Successful exploitation allows injection of arbitrary IMAP commands, potentially leading to unauthorized actions on IMAP servers or clients. This can result in information disclosure or integrity violations within email systems. There is no risk of arbitrary code execution. The impact is therefore limited to the IMAP protocol level and email data integrity and confidentiality.
Mitigation Recommendations
Fixed versions 0.4.24, 0.5.14, and 0.6.4 of the net-imap library address this vulnerability. Red Hat has released security updates for affected products, including Red Hat Enterprise Linux 7 Extended Lifecycle Support. Users should apply these official patches to remediate the issue. No alternative mitigations meeting Red Hat's criteria are currently available. Users are advised to upgrade to patched versions to eliminate the vulnerability.
CVE-2026-42258: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') in ruby net-imap
Description
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.
CVSS v4.0
Score 5.8medium
Affected software
ruby
net-imap
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Ruby net-imap library, which implements IMAP client functionality, contains a command injection vulnerability (CWE-77 and CWE-93) in versions prior to 0.4.24, 0.5.14, and 0.6.4. This vulnerability arises from improper neutralization of special elements in symbol arguments passed to IMAP commands, enabling injection of arbitrary IMAP commands. Exploitation could allow an attacker to perform unauthorized IMAP operations, impacting confidentiality and integrity of email data. Red Hat advisories confirm the issue and provide patched versions. The vulnerability does not permit arbitrary code execution and is limited to email system impacts.
Potential Impact
Successful exploitation allows injection of arbitrary IMAP commands, potentially leading to unauthorized actions on IMAP servers or clients. This can result in information disclosure or integrity violations within email systems. There is no risk of arbitrary code execution. The impact is therefore limited to the IMAP protocol level and email data integrity and confidentiality.
Mitigation Recommendations
Fixed versions 0.4.24, 0.5.14, and 0.6.4 of the net-imap library address this vulnerability. Red Hat has released security updates for affected products, including Red Hat Enterprise Linux 7 Extended Lifecycle Support. Users should apply these official patches to remediate the issue. No alternative mitigations meeting Red Hat's criteria are currently available. Users are advised to upgrade to patched versions to eliminate the vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-26T11:53:27.704Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-42258","vendor":"Red Hat"}]
Threat ID: 69ff93c0cbff5d86106e459b
Added to database: 05/09/2026, 20:06:24 UTC
Last enriched: 08/05/2026, 13:00:03 UTC
Last updated: 09/14/2026, 10:01:30 UTC
Views: 150
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.