PatchSiren cyber security CVE debrief
CVE-2026-42258 ruby CVE debrief
CVE-2026-42258 is a medium-severity injection issue in Ruby’s Net::IMAP client. According to the NVD record and GitHub security advisory references, symbol arguments passed to IMAP commands could be abused for CRLF injection / IMAP command injection. The issue was publicly disclosed on 2026-05-09 and is patched in Net::IMAP 0.4.24, 0.5.14, and 0.6.4.
- Vendor
- ruby
- Product
- net-imap
- CVSS
- MEDIUM 5.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-09
- Original CVE updated
- 2026-08-24
- Advisory published
- 2026-05-09
- Advisory updated
- 2026-08-24
Who should care
Teams maintaining Ruby applications that depend on the net-imap gem, especially if application code passes symbol arguments into IMAP command methods.
Technical summary
The vulnerability allows symbol arguments supplied to Net::IMAP commands to be interpreted in a way that can inject CRLF content or alter the resulting IMAP command stream. The NVD metadata maps this to CWE-77 and CWE-93 and records the issue as fixed by Net::IMAP releases 0.4.24, 0.5.14, and 0.6.4.
Defensive priority
Medium priority for Ruby environments that use Net::IMAP; prioritize upgrade if the library is present in production or handles externally influenced input.
Recommended defensive actions
- Upgrade Net::IMAP to 0.4.24, 0.5.14, or 0.6.4, depending on the branch you use.
- Inventory Ruby services and gems to confirm whether net-imap is present and which version is deployed.
- Review code paths that pass symbol arguments into IMAP command methods and remove any dependence on externally influenced values.
- After upgrading, test IMAP workflows that use symbol arguments to confirm expected behavior.
- If immediate upgrading is not possible, restrict or avoid the affected call patterns until the patched version is deployed.
Evidence notes
This debrief is based on the official NVD CVE metadata and GitHub Security Advisory references supplied in the source corpus. The source record identifies Net::IMAP in Ruby as the affected component, describes symbol-argument CRLF / IMAP command injection, and lists fixed versions 0.4.24, 0.5.14, and 0.6.4. Weakness mappings in the source record include CWE-77 and CWE-93.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42258 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42258
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42258 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42258
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ruby/net-imap/releases/tag/v0.4.24
-
Source reference
Unverified legacy reference
URL: https://github.com/ruby/net-imap/releases/tag/v0.5.14
-
Source reference
Unverified legacy reference
URL: https://github.com/ruby/net-imap/releases/tag/v0.6.4
-
Source reference
Unverified legacy reference
URL: https://github.com/ruby/net-imap/security/advisories/GHSA-75xq-5h9v-w6px
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.