Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 76%

CVE-2026-42246: CWE-392: Missing Report of Error Condition in ruby net-imap

0
High
Published: 05/09/2026 (05/09/2026, 19:33:17 UTC)
Source: GCVE Database
Vendor/Project: ruby
Product: net-imap

Description

CVE-2026-42246 is a vulnerability in the Ruby net-imap library affecting the STARTTLS functionality. A man-in-the-middle attacker can cause the Net::IMAP#starttls method to report success without actually establishing a TLS session, allowing sensitive information to be transmitted in cleartext. This flaw affects multiple versions of net-imap prior to 0.3.10, 0.4.24, 0.5.14, and 0.6.4. The vulnerability has been patched in these versions. Red Hat has released security updates addressing this issue for their Ruby packages. Users are advised to prefer implicit TLS (IMAPS on port 993) as a mitigation to avoid the vulnerable STARTTLS negotiation path.

CVSS v4.0

Score 7.6high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
Passive
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected software

redhat/ruby
pkg:rpm/redhat/ruby
Affected versions
=9.8<9.8

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 18:36:01 UTC

Technical Analysis

The Ruby net-imap library's STARTTLS implementation improperly handles certain responses during TLS negotiation. Specifically, a man-in-the-middle attacker can inject a forged tagged OK response before the client completes the STARTTLS command, causing the client to believe TLS has been successfully established when it has not. This allows interception and modification of sensitive data transmitted over the connection. The vulnerability affects net-imap versions prior to 0.3.10, 0.4.24, 0.5.14, and 0.6.4. Red Hat's advisory confirms the issue affects their Ruby packages bundled with net-imap and provides patched versions. The attack complexity is high, requiring network interception and timing precision. Red Hat recommends switching to implicit TLS connections as a temporary mitigation.

Potential Impact

Successful exploitation allows a man-in-the-middle attacker to bypass TLS encryption on IMAP connections that use STARTTLS, potentially exposing authentication credentials, email contents, and other sensitive information. It also enables unauthorized modification of data exchanged over the affected connection. The vulnerability impacts confidentiality and integrity but does not affect availability. The CVSS v3.1 base score is 7.4 (high severity).

Mitigation Recommendations

A fix is available in net-imap versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4 and corresponding patched Ruby packages from Red Hat. Users should apply these updates promptly. As a temporary workaround, users are strongly encouraged to switch from explicit TLS upgrading mechanisms (STARTTLS on port 143) to implicit TLS connections (IMAPS on port 993), which are not vulnerable to this attack vector. This mitigation bypasses the vulnerable STARTTLS negotiation entirely.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:33512
Cve Count
2
Additional Cves
["CVE-2026-42258"]
Cvss Version
null

Threat ID: 6a4452df27e9c797198e0daa

Added to database: 06/30/2026, 23:35:59 UTC

Last enriched: 08/05/2026, 18:36:01 UTC

Last updated: 08/14/2026, 00:41:12 UTC

Views: 154

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses