← Vulnerability feed

Vulnerability record · CVE-2026-42246 · published 9 May 2026

CVE-2026-42246: Ruby-lang net\ vulnerability

Ruby Lang · Net\

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.

7.6 CVSS 4.0 High EPSS 0.40% · top 68.8% CWE-392 · CWE-392CWE-393 · CWE-393
7.6CVSS 4.0 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
31References
24 Aug 2026Last modified by NVD

Description

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 Patch
https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e Patch
https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c Patch
https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da Patch
https://github.com/ruby/net-imap/releases/tag/v0.3.10 Release Notes
https://github.com/ruby/net-imap/releases/tag/v0.4.24 Release Notes
https://github.com/ruby/net-imap/releases/tag/v0.5.14 Release Notes
https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp MitigationVendor Advisory
https://access.redhat.com/errata/RHSA-2026:33462
https://access.redhat.com/errata/RHSA-2026:33512
https://access.redhat.com/errata/RHSA-2026:33514
https://access.redhat.com/errata/RHSA-2026:33515
https://access.redhat.com/errata/RHSA-2026:33540
https://access.redhat.com/errata/RHSA-2026:33551
https://access.redhat.com/errata/RHSA-2026:33552
https://access.redhat.com/errata/RHSA-2026:33565
https://access.redhat.com/errata/RHSA-2026:33576
https://access.redhat.com/errata/RHSA-2026:33577
https://access.redhat.com/errata/RHSA-2026:33630
https://access.redhat.com/errata/RHSA-2026:33721
https://access.redhat.com/errata/RHSA-2026:34076
https://access.redhat.com/errata/RHSA-2026:35834
https://access.redhat.com/errata/RHSA-2026:35866
https://access.redhat.com/errata/RHSA-2026:35867
https://access.redhat.com/errata/RHSA-2026:35895
https://access.redhat.com/errata/RHSA-2026:36099
https://access.redhat.com/errata/RHSA-2026:37238
https://access.redhat.com/errata/RHSA-2026:37397
https://access.redhat.com/security/cve/CVE-2026-42246
https://bugzilla.redhat.com/show_bug.cgi?id=2468499
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json

Track CVE-2026-42246 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2026-42246), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.