CVE-2026-42246: CWE-392: Missing Report of Error Condition in ruby net-imap
CVE-2026-42246 is a vulnerability in the Ruby net-imap library affecting the STARTTLS functionality. A man-in-the-middle attacker can cause the Net::IMAP#starttls method to report success without actually establishing a TLS session, allowing sensitive information to be transmitted in cleartext. This flaw affects multiple versions of net-imap prior to 0.3.10, 0.4.24, 0.5.14, and 0.6.4. The vulnerability has been patched in these versions. Red Hat has released security updates addressing this issue for their Ruby packages. Users are advised to prefer implicit TLS (IMAPS on port 993) as a mitigation to avoid the vulnerable STARTTLS negotiation path.
AI Analysis
Technical Summary
The Ruby net-imap library's STARTTLS implementation improperly handles certain responses during TLS negotiation. Specifically, a man-in-the-middle attacker can inject a forged tagged OK response before the client completes the STARTTLS command, causing the client to believe TLS has been successfully established when it has not. This allows interception and modification of sensitive data transmitted over the connection. The vulnerability affects net-imap versions prior to 0.3.10, 0.4.24, 0.5.14, and 0.6.4. Red Hat's advisory confirms the issue affects their Ruby packages bundled with net-imap and provides patched versions. The attack complexity is high, requiring network interception and timing precision. Red Hat recommends switching to implicit TLS connections as a temporary mitigation.
Potential Impact
Successful exploitation allows a man-in-the-middle attacker to bypass TLS encryption on IMAP connections that use STARTTLS, potentially exposing authentication credentials, email contents, and other sensitive information. It also enables unauthorized modification of data exchanged over the affected connection. The vulnerability impacts confidentiality and integrity but does not affect availability. The CVSS v3.1 base score is 7.4 (high severity).
Mitigation Recommendations
A fix is available in net-imap versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4 and corresponding patched Ruby packages from Red Hat. Users should apply these updates promptly. As a temporary workaround, users are strongly encouraged to switch from explicit TLS upgrading mechanisms (STARTTLS on port 143) to implicit TLS connections (IMAPS on port 993), which are not vulnerable to this attack vector. This mitigation bypasses the vulnerable STARTTLS negotiation entirely.
CVE-2026-42246: CWE-392: Missing Report of Error Condition in ruby net-imap
Description
CVE-2026-42246 is a vulnerability in the Ruby net-imap library affecting the STARTTLS functionality. A man-in-the-middle attacker can cause the Net::IMAP#starttls method to report success without actually establishing a TLS session, allowing sensitive information to be transmitted in cleartext. This flaw affects multiple versions of net-imap prior to 0.3.10, 0.4.24, 0.5.14, and 0.6.4. The vulnerability has been patched in these versions. Red Hat has released security updates addressing this issue for their Ruby packages. Users are advised to prefer implicit TLS (IMAPS on port 993) as a mitigation to avoid the vulnerable STARTTLS negotiation path.
CVSS v4.0
Score 7.6high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Ruby net-imap library's STARTTLS implementation improperly handles certain responses during TLS negotiation. Specifically, a man-in-the-middle attacker can inject a forged tagged OK response before the client completes the STARTTLS command, causing the client to believe TLS has been successfully established when it has not. This allows interception and modification of sensitive data transmitted over the connection. The vulnerability affects net-imap versions prior to 0.3.10, 0.4.24, 0.5.14, and 0.6.4. Red Hat's advisory confirms the issue affects their Ruby packages bundled with net-imap and provides patched versions. The attack complexity is high, requiring network interception and timing precision. Red Hat recommends switching to implicit TLS connections as a temporary mitigation.
Potential Impact
Successful exploitation allows a man-in-the-middle attacker to bypass TLS encryption on IMAP connections that use STARTTLS, potentially exposing authentication credentials, email contents, and other sensitive information. It also enables unauthorized modification of data exchanged over the affected connection. The vulnerability impacts confidentiality and integrity but does not affect availability. The CVSS v3.1 base score is 7.4 (high severity).
Mitigation Recommendations
A fix is available in net-imap versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4 and corresponding patched Ruby packages from Red Hat. Users should apply these updates promptly. As a temporary workaround, users are strongly encouraged to switch from explicit TLS upgrading mechanisms (STARTTLS on port 143) to implicit TLS connections (IMAPS on port 993), which are not vulnerable to this attack vector. This mitigation bypasses the vulnerable STARTTLS negotiation entirely.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:33512
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-42258"]
- Cvss Version
- null
Threat ID: 6a4452df27e9c797198e0daa
Added to database: 06/30/2026, 23:35:59 UTC
Last enriched: 08/05/2026, 18:36:01 UTC
Last updated: 08/14/2026, 00:41:12 UTC
Views: 154
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.