{"id":"CVE-2026-42257","aliases":["GHSA-hm49-wcqc-g2xg"],"url":"https://o3.security/vulnerability/CVE-2026-42257","summary":"net-imap: Command Injection via \"raw\" arguments to multiple commands","details":"Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.","published":"2026-05-09T19:39:48.398Z","modified":"2026-08-07T11:51:05.652254349Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"net-imap","fixedVersion":"0.6.4"},{"ecosystem":"RubyGems","name":"net-imap","fixedVersion":"0.5.14"},{"ecosystem":"RubyGems","name":"net-imap","fixedVersion":"0.4.24"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ruby/net-imap/releases/tag/v0.4.24"},{"type":"WEB","url":"https://github.com/ruby/net-imap/releases/tag/v0.5.14"},{"type":"WEB","url":"https://github.com/ruby/net-imap/releases/tag/v0.6.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42257.json"},{"type":"ADVISORY","url":"https://github.com/ruby/net-imap/security/advisories/GHSA-hm49-wcqc-g2xg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42257"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:51:05.652254349Z"}}