<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:52:05.092261+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:33512</id>
    <title>ALSA-2026:33512 — Important: ruby security update</title>
    <updated>2026-10-03T06:52:05.736965+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: ruby, AlmaLinux:9: ruby-default-gems, AlmaLinux:9: ruby-devel, AlmaLinux:9: ruby-doc, AlmaLinux:9: ruby-libs, AlmaLinux:9: rubygem-bigdecimal, AlmaLinux:9: rubygem-bundler, AlmaLinux:9: rubygem-io-console, AlmaLinux:9: rubygem-irb, AlmaLinux:9: rubygem-json and 12 more</p>
<p>Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.</p>
<p>Security Fix(es):</p>
<p>* ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258)
  * net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:33512"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-42258</id>
    <title>BELL-CVE-2026-42258</title>
    <updated>2026-10-03T06:52:05.737069+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: ruby-net-imap, Alpaquita:stream: ruby-net-imap</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-42258"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-imap-backup-cve-2026-42258</id>
    <title>BREW-imap-backup-CVE-2026-42258 — net-imap vulnerable to command Injection via unvalidated Symbol inputs</title>
    <updated>2026-10-03T06:52:05.737095+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: imap-backup</p>
<p>### Summary</p>
<p>Symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands.</p>
<p>### Details</p>
<p>Symbol arguments represent IMAP "system flags", which are formatted as "atoms" (with no quoting) with a `"\"` prefix.  Vulnerable versions of Net::IMAP sends the symbol name directly to the socket, with no validation.</p>
<p>Because the Symbol input is unvalidated, it could contain invalid `flag` characters, including `SP` and `CRLF`, which could be used to finish the current command and inject new commands.</p>
<p>Although IMAP `flag` arguments are only valid input for a few IMAP commands, most Net::IMAP commands use generic argument handling, and will allow Symbol (`flag`) inputs.</p>
<p>Note also that the list of valid symbol inputs should be restricted to an enumerated set of standard RFC defined flag types, which have each been given specific defined semantics.  Any user-provided values outside of that list of standard "system flags" needs to use the IMAP `keyword` syntax, which are sent as atoms, i.e: string inputs. Under no circumstances should `#to_sym` ever be called on unvetted user-provided input: that will always be a bug in the calling code for the simple reason that `user_input_atom` is  as `\user_input_atom`.</p>
<p>For forward compatibility with future IMAP extentions, Net::IMAP, does not restrict flag inputs to an enumerated list.  That is the responsibility of the calling application code, which knows which flag semantics…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-imap-backup-cve-2026-42258"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</id>
    <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T06:52:05.737140+00:00</updated>
    <content>certfr-2026-avi-0958</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-rg00675</id>
    <title>Withdrawn: CLEANSTART-2026-RG00675 — Security fixes for CVE-2026-33637, CVE-2026-42245, CVE-2026-42246, CVE-2026-42256, CVE-2026-42257, CVE-2026-42258, ghsa…</title>
    <updated>2026-10-03T06:52:05.737158+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: ruby-fluentd-1.19</p>
<p>Multiple security vulnerabilities affect the ruby-fluentd-1.19 package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-rg00675"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362269</id>
    <title>EUVD-2026-362269</title>
    <updated>2026-10-03T06:52:05.737180+00:00</updated>
    <content>EUVD-2026-362269</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362269"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42258</id>
    <title>fkie_cve-2026-42258</title>
    <updated>2026-10-03T06:52:05.737192+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42258"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-75xq-5h9v-w6px</id>
    <title>GHSA-75xq-5h9v-w6px — net-imap vulnerable to command Injection via unvalidated Symbol inputs</title>
    <updated>2026-10-03T06:52:05.737213+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: net-imap</p>
<p>### Summary</p>
<p>Symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands.</p>
<p>### Details</p>
<p>Symbol arguments represent IMAP "system flags", which are formatted as "atoms" (with no quoting) with a `"\"` prefix.  Vulnerable versions of Net::IMAP sends the symbol name directly to the socket, with no validation.</p>
<p>Because the Symbol input is unvalidated, it could contain invalid `flag` characters, including `SP` and `CRLF`, which could be used to finish the current command and inject new commands.</p>
<p>Although IMAP `flag` arguments are only valid input for a few IMAP commands, most Net::IMAP commands use generic argument handling, and will allow Symbol (`flag`) inputs.</p>
<p>Note also that the list of valid symbol inputs should be restricted to an enumerated set of standard RFC defined flag types, which have each been given specific defined semantics.  Any user-provided values outside of that list of standard "system flags" needs to use the IMAP `keyword` syntax, which are sent as atoms, i.e: string inputs. Under no circumstances should `#to_sym` ever be called on unvetted user-provided input: that will always be a bug in the calling code for the simple reason that `user_input_atom` is  as `\user_input_atom`.</p>
<p>For forward compatibility with future IMAP extentions, Net::IMAP, does not restrict flag inputs to an enumerated list.  That is the responsibility of the calling application code, which knows which flag semantics…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-75xq-5h9v-w6px"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42258</id>
    <title>msrc_CVE-2026-42258 — net-imap: Command Injection via unvalidated Symbol inputs</title>
    <updated>2026-10-03T06:52:05.737268+00:00</updated>
    <content>msrc_CVE-2026-42258</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-42258"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2578</id>
    <title>OESA-2026-2578 — ruby security update</title>
    <updated>2026-10-03T06:52:05.737287+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: ruby, openEuler:22.03-LTS-SP4: ruby, openEuler:24.03-LTS-SP1: ruby, openEuler:24.03-LTS-SP3: ruby</p>
<p>Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).

Security Fix(es):</p>
<p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client&amp;apos;s CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.(CVE-2026-42245)</p>
<p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return &amp;quot;successfully&amp;quot;, without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.(CVE-2026-42246)</p>
<p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.(CVE-2026…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2578"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21878-1</id>
    <title>openSUSE-SU-2026:21878-1 — Security update for ruby3.4</title>
    <updated>2026-10-03T06:52:05.737328+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ruby3.4</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21878-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:33630</id>
    <title>RHSA-2026:33630 — Red Hat Security Advisory: ruby security update</title>
    <updated>2026-10-03T06:52:05.737348+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:33630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:33512</id>
    <title>RLSA-2026:33512 — Important: ruby security update</title>
    <updated>2026-10-03T06:52:05.737365+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: ruby</p>
<p>Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.</p>
<p>Security Fix(es):</p>
<p>* ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258)</p>
<p>* net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:33512"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42258</id>
    <title>UBUNTU-CVE-2026-42258</title>
    <updated>2026-10-03T06:52:05.737388+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:18.04:LTS: jruby, Ubuntu:Pro:20.04:LTS: ruby2.7, Ubuntu:20.04:LTS: jruby, Ubuntu:22.04:LTS: ruby3.0, Ubuntu:24.04:LTS: jruby, Ubuntu:24.04:LTS: ruby3.2 and 4 more</p>
<p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42258"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2117</id>
    <title>WID-SEC-W-2026-2117 — HCL BigFix Compliance (Ruby): Mehrere Schwachstellen</title>
    <updated>2026-10-03T06:52:05.737423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in HCL BigFix Compliance ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2117"/>
  </entry>
</feed>
