CVE-2026-42246CWE-325CWE-392CWE-393CWE-636CWE-754CWE-841

CVE-2026-42246

High · published May 10, 2026

CVSS v3.1
7.4
EPSS
0%
Percentile
23.7
In the wild
Unconfirmed
What it is

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.

The record
Technical detail
CVSS v3.1
7.4 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00312 · 23.7th percentile
Weaknesses
CWE-325 · Missing Cryptographic Step; CWE-392 · Missing Report of Error Condition; CWE-393 · Return of Wrong Status Code; CWE-636 · Not Failing Securely ('Failing Open'); CWE-754 · Improper Check for Unusual or Exceptional Conditions; CWE-841 · Improper Enforcement of Behavioral Workflow
Published
2026-05-10T00:16Z
Affected products (4)
ProductVersionsFixed in
ruby-lang/net\< 0.3.100.3.10
ruby-lang/net\≥ 0.4.0, < 0.4.240.4.24
ruby-lang/net\≥ 0.5.0, < 0.5.140.5.14
ruby-lang/net\≥ 0.6.0, < 0.6.40.6.4
References (31)
https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618 · [email protected]https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485e · [email protected]https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42c · [email protected]https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873da · [email protected]https://github.com/ruby/net-imap/releases/tag/v0.3.10 · [email protected]https://github.com/ruby/net-imap/releases/tag/v0.4.24 · [email protected]https://github.com/ruby/net-imap/releases/tag/v0.5.14 · [email protected]https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcp · [email protected]https://access.redhat.com/errata/RHSA-2026:33462 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33512 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33514 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33515 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33540 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33551 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33552 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33565 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33576 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33577 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33630 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:33721 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:34076 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:35834 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:35866 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:35867 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:35895 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:36099 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:37238 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:37397 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/security/cve/CVE-2026-42246 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://bugzilla.redhat.com/show_bug.cgi?id=2468499 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42246.json · 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
EPSS history
Timeline
  • 09 MAY 19:33Z
    net-imap vulnerable to STARTTLS stripping via invalid response timing
    cvelistv5