Ruby-Lang / Net\
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-42258 | net-imap: Command Injection via unvalidated Symbol inputs | MEDIUM | 5.8 | May 9, 2026 |
| CVE-2026-42257 | net-imap: Command Injection via "raw" arguments to multiple commands | MEDIUM | 5.8 | May 9, 2026 |
| CVE-2026-42256 | net-imap: Denial of service via high iteration count for `SCRAM-*` authentication | MEDIUM | 6.0 | May 9, 2026 |
| CVE-2026-42245 | net-imap: Quadratic complexity when reading response literals | LOW | 2.3 | May 9, 2026 |
| CVE-2026-42246 | net-imap vulnerable to STARTTLS stripping via invalid response timing | HIGH | 7.6 | May 9, 2026 |
| CVE-2025-43857 | net-imap rubygem vulnerable to possible DoS by memory exhaustion | MEDIUM | 6.0 | Apr 28, 2025 |
Showing 1 to 6 of 6 CVEs