<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:35:40.414914+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:33515</id>
    <title>ALSA-2026:33515 — Important: ruby:3.3 security update</title>
    <updated>2026-10-03T15:35:41.583406+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: ruby, AlmaLinux:8: ruby-bundled-gems, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bundler and 20 more</p>
<p>Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.</p>
<p>Security Fix(es):</p>
<p>* ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses (CVE-2026-42245)
  * ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258)
  * net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:33515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-42245</id>
    <title>BELL-CVE-2026-42245</title>
    <updated>2026-10-03T15:35:41.583544+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: ruby-net-imap, Alpaquita:stream: ruby-net-imap</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-42245"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-imap-backup-cve-2026-42245</id>
    <title>BREW-imap-backup-CVE-2026-42245 — net-imap has quadratic complexity when reading response literals</title>
    <updated>2026-10-03T15:35:41.583596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: imap-backup</p>
<p>### Summary</p>
<p>`Net::IMAP::ResponseReader` has quadratic time complexity when reading large responses containing many string literals.  A hostile server can send responses which are crafted to exhaust the client's CPU for a denial of service attack.</p>
<p>### Details</p>
<p>For each literal in a response, `ResponseReader` rescans the entire growing response buffer.  The regular expression that is used to scan the response buffer runs in linear time.  With many literals, this becomes O(n²) total work.  The regular expression should run in constant time: it is anchored to the end and only the last 23 bytes of the buffer are relevant.</p>
<p>Because the algorithmic complexity is super-linear, this bypasses protection from `max_response_size`: a response can stay well below the default size limit while still causing very large CPU cost.</p>
<p>`Net::IMAP::ResponseReader` runs continuously in the receiver thread until the connection closes.</p>
<p>### Impact</p>
<p>This consumes disproportionate CPU time in the client's receiver thread.  A hostile server could use this to exhaust the client's CPU for a denial of service attack.</p>
<p>For a response near the default `max_response_size`, each individual regexp scan could take between 100 to 200ms on common modern hardware, and this may be repeated 200k times per megabyte of response.  While the regexp is scanning, it retains the Global VM lock, preventing other threads from running.</p>
<p>Although other threads should not be _completely_ blocked, their run time will be signific…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-imap-backup-cve-2026-42245"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</id>
    <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T15:35:41.583652+00:00</updated>
    <content>certfr-2026-avi-0958</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-gp85472</id>
    <title>CLEANSTART-2026-GP85472 — Security fix for CVE-2026-42245 applied in: ruby-fluentd-1.19 1.19.2-r2</title>
    <updated>2026-10-03T15:35:41.583673+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: ruby-fluentd-1.19</p>
<p>Security vulnerability affects the ruby-fluentd-1.19 package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-gp85472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-317412</id>
    <title>EUVD-2026-317412</title>
    <updated>2026-10-03T15:35:41.583695+00:00</updated>
    <content>EUVD-2026-317412</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-317412"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42245</id>
    <title>fkie_cve-2026-42245</title>
    <updated>2026-10-03T15:35:41.583707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client's CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42245"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q2mw-fvj9-vvcw</id>
    <title>GHSA-q2mw-fvj9-vvcw — net-imap has quadratic complexity when reading response literals</title>
    <updated>2026-10-03T15:35:41.583732+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: net-imap</p>
<p>### Summary</p>
<p>`Net::IMAP::ResponseReader` has quadratic time complexity when reading large responses containing many string literals.  A hostile server can send responses which are crafted to exhaust the client's CPU for a denial of service attack.</p>
<p>### Details</p>
<p>For each literal in a response, `ResponseReader` rescans the entire growing response buffer.  The regular expression that is used to scan the response buffer runs in linear time.  With many literals, this becomes O(n²) total work.  The regular expression should run in constant time: it is anchored to the end and only the last 23 bytes of the buffer are relevant.</p>
<p>Because the algorithmic complexity is super-linear, this bypasses protection from `max_response_size`: a response can stay well below the default size limit while still causing very large CPU cost.</p>
<p>`Net::IMAP::ResponseReader` runs continuously in the receiver thread until the connection closes.</p>
<p>### Impact</p>
<p>This consumes disproportionate CPU time in the client's receiver thread.  A hostile server could use this to exhaust the client's CPU for a denial of service attack.</p>
<p>For a response near the default `max_response_size`, each individual regexp scan could take between 100 to 200ms on common modern hardware, and this may be repeated 200k times per megabyte of response.  While the regexp is scanning, it retains the Global VM lock, preventing other threads from running.</p>
<p>Although other threads should not be _completely_ blocked, their run time will be signific…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q2mw-fvj9-vvcw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2578</id>
    <title>OESA-2026-2578 — ruby security update</title>
    <updated>2026-10-03T15:35:41.583774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: ruby, openEuler:22.03-LTS-SP4: ruby, openEuler:24.03-LTS-SP1: ruby, openEuler:24.03-LTS-SP3: ruby</p>
<p>Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).

Security Fix(es):</p>
<p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client&amp;apos;s CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.(CVE-2026-42245)</p>
<p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return &amp;quot;successfully&amp;quot;, without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.(CVE-2026-42246)</p>
<p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.(CVE-2026…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2578"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:33515</id>
    <title>RHSA-2026:33515 — Red Hat Security Advisory: ruby:3.3 security update</title>
    <updated>2026-10-03T15:35:41.583827+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:33515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:33551</id>
    <title>RHSA-2026:33551 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-03T15:35:41.583879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS ruby/net-imap: ruby: Net::IMAP: Denial of Service via large iteration count in SCRAM authentication net-imap: Net::IMAP: Command injection via non-synchronizing literals net-imap: rubygem-net-imap: Net::IMAP: Denial of Service via malformed command input net-imap: Net::IMAP: Arbitrary IMAP command injection due to improper input validation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:33551"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:33515</id>
    <title>RLSA-2026:33515 — Important: ruby:3.3 security update</title>
    <updated>2026-10-03T15:35:41.583910+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: ruby, Rocky Linux:8: rubygem-abrt, Rocky Linux:8: rubygem-mysql2, Rocky Linux:8: rubygem-pg</p>
<p>Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.</p>
<p>Security Fix(es):</p>
<p>* ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses (CVE-2026-42245)</p>
<p>* ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258)</p>
<p>* net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:33515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42245</id>
    <title>UBUNTU-CVE-2026-42245</title>
    <updated>2026-10-03T15:35:41.583949+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:25.10: jruby, Ubuntu:25.10: ruby3.3</p>
<p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client's CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42245"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2117</id>
    <title>WID-SEC-W-2026-2117 — HCL BigFix Compliance (Ruby): Mehrere Schwachstellen</title>
    <updated>2026-10-03T15:35:41.583974+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in HCL BigFix Compliance ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2117"/>
  </entry>
</feed>
