<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:02:02 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:10217 — Moderate: ruby:3.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:10217</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ruby, AlmaLinux:8: ruby-bundled-gems, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bundler and 20 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* net-imap: Net::IMAP vulnerable to possible DoS by memory exhaustion (CVE-2025-25186)
  * CGI: Denial of Service in CGI::Cookie.parse (CVE-2025-27219)
  * uri: userinfo leakage in URI#join, URI#merge and URI#+ (CVE-2025-27221)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ruby, AlmaLinux:8: ruby-bundled-gems, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bundler and 20 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* net-imap: Net::IMAP vulnerable to possible DoS by memory exhaustion (CVE-2025-25186)
  * CGI: Denial of Service in CGI::Cookie.parse (CVE-2025-27219)
  * uri: userinfo leakage in URI#join, URI#merge and URI#+ (CVE-2025-27221)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:10217</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-25186</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-25186</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: ruby-net-imap&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: ruby-net-imap&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-25186</guid>
    </item>
    <item>
      <title>BREW-mailcatcher-CVE-2025-25186 — Possible DoS by memory exhaustion in net-imap</title>
      <link>https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2025-25186</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mailcatcher&lt;/p&gt;
&lt;p&gt;### Summary
There is a possibility for denial of service by memory exhaustion in `net-imap`&amp;#39;s response parser.  At any time while the client is connected, a malicious server can send  can send highly compressed `uid-set` data which is automatically read by the client&amp;#39;s receiver thread.  The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges.&lt;/p&gt;
&lt;p&gt;### Details
IMAP&amp;#39;s `uid-set` and `sequence-set` formats can compress ranges of numbers, for example: `&amp;#34;1,2,3,4,5&amp;#34;` and `&amp;#34;1:5&amp;#34;` both represent the same set.  When `Net::IMAP::ResponseParser` receives `APPENDUID` or `COPYUID` response codes, it expands each `uid-set` into an array of integers.  On a 64 bit system, these arrays will expand to 8 bytes for each number in the set.  A malicious IMAP server may send specially crafted `APPENDUID` or `COPYUID` responses with very large `uid-set` ranges.&lt;/p&gt;
&lt;p&gt;The `Net::IMAP` client parses each server response in a separate thread, as soon as each responses is received from the server.  This attack works even when the client does not handle the `APPENDUID` or `COPYUID` responses.&lt;/p&gt;
&lt;p&gt;Malicious inputs:&lt;/p&gt;
&lt;p&gt;```ruby
# 40 bytes expands to ~1.6GB:
&amp;#34;* OK [COPYUID 1 1:99999999 1:99999999]\r\n&amp;#34;&lt;/p&gt;
&lt;p&gt;# Worst *valid* input scenario (using uint32 max),
# 44 bytes expands to 64GiB:
&amp;#34;* OK [COPYUID 1 1:4294967295 1:4294967295]\r\n&amp;#34;&lt;/p&gt;
&lt;p&gt;# Numbers must be non-zero uint32, but this isn&amp;#39;t validated.  Arrays larger than
# UINT32_MAX can be cre…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mailcatcher&lt;/p&gt;
&lt;p&gt;### Summary
There is a possibility for denial of service by memory exhaustion in `net-imap`&amp;#39;s response parser.  At any time while the client is connected, a malicious server can send  can send highly compressed `uid-set` data which is automatically read by the client&amp;#39;s receiver thread.  The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges.&lt;/p&gt;
&lt;p&gt;### Details
IMAP&amp;#39;s `uid-set` and `sequence-set` formats can compress ranges of numbers, for example: `&amp;#34;1,2,3,4,5&amp;#34;` and `&amp;#34;1:5&amp;#34;` both represent the same set.  When `Net::IMAP::ResponseParser` receives `APPENDUID` or `COPYUID` response codes, it expands each `uid-set` into an array of integers.  On a 64 bit system, these arrays will expand to 8 bytes for each number in the set.  A malicious IMAP server may send specially crafted `APPENDUID` or `COPYUID` responses with very large `uid-set` ranges.&lt;/p&gt;
&lt;p&gt;The `Net::IMAP` client parses each server response in a separate thread, as soon as each responses is received from the server.  This attack works even when the client does not handle the `APPENDUID` or `COPYUID` responses.&lt;/p&gt;
&lt;p&gt;Malicious inputs:&lt;/p&gt;
&lt;p&gt;```ruby
# 40 bytes expands to ~1.6GB:
&amp;#34;* OK [COPYUID 1 1:99999999 1:99999999]\r\n&amp;#34;&lt;/p&gt;
&lt;p&gt;# Worst *valid* input scenario (using uint32 max),
# 44 bytes expands to 64GiB:
&amp;#34;* OK [COPYUID 1 1:4294967295 1:4294967295]\r\n&amp;#34;&lt;/p&gt;
&lt;p&gt;# Numbers must be non-zero uint32, but this isn&amp;#39;t validated.  Arrays larger than
# UINT32_MAX can be cre…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-mailcatcher-cve-2025-25186</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</link>
      <description>certfr-2025-avi-0622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</guid>
    </item>
    <item>
      <title>EUVD-2026-214879</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-214879</link>
      <description>EUVD-2026-214879</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-214879</guid>
    </item>
    <item>
      <title>fkie_cve-2025-25186</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-25186</link>
      <description>&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`&amp;#39;s response parser.  At any time while the client is connected, a malicious server can send  can send highly compressed `uid-set` data which is automatically read by the client&amp;#39;s receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`&amp;#39;s response parser.  At any time while the client is connected, a malicious server can send  can send highly compressed `uid-set` data which is automatically read by the client&amp;#39;s receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-25186</guid>
    </item>
    <item>
      <title>GHSA-7fc5-f82f-cx69 — Possible DoS by memory exhaustion in net-imap</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7fc5-f82f-cx69</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: net-imap&lt;/p&gt;
&lt;p&gt;### Summary
There is a possibility for denial of service by memory exhaustion in `net-imap`&amp;#39;s response parser.  At any time while the client is connected, a malicious server can send  can send highly compressed `uid-set` data which is automatically read by the client&amp;#39;s receiver thread.  The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges.&lt;/p&gt;
&lt;p&gt;### Details
IMAP&amp;#39;s `uid-set` and `sequence-set` formats can compress ranges of numbers, for example: `&amp;#34;1,2,3,4,5&amp;#34;` and `&amp;#34;1:5&amp;#34;` both represent the same set.  When `Net::IMAP::ResponseParser` receives `APPENDUID` or `COPYUID` response codes, it expands each `uid-set` into an array of integers.  On a 64 bit system, these arrays will expand to 8 bytes for each number in the set.  A malicious IMAP server may send specially crafted `APPENDUID` or `COPYUID` responses with very large `uid-set` ranges.&lt;/p&gt;
&lt;p&gt;The `Net::IMAP` client parses each server response in a separate thread, as soon as each responses is received from the server.  This attack works even when the client does not handle the `APPENDUID` or `COPYUID` responses.&lt;/p&gt;
&lt;p&gt;Malicious inputs:&lt;/p&gt;
&lt;p&gt;```ruby
# 40 bytes expands to ~1.6GB:
&amp;#34;* OK [COPYUID 1 1:99999999 1:99999999]\r\n&amp;#34;&lt;/p&gt;
&lt;p&gt;# Worst *valid* input scenario (using uint32 max),
# 44 bytes expands to 64GiB:
&amp;#34;* OK [COPYUID 1 1:4294967295 1:4294967295]\r\n&amp;#34;&lt;/p&gt;
&lt;p&gt;# Numbers must be non-zero uint32, but this isn&amp;#39;t validated.  Arrays larger than
# UINT32_MAX can be cre…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: net-imap&lt;/p&gt;
&lt;p&gt;### Summary
There is a possibility for denial of service by memory exhaustion in `net-imap`&amp;#39;s response parser.  At any time while the client is connected, a malicious server can send  can send highly compressed `uid-set` data which is automatically read by the client&amp;#39;s receiver thread.  The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges.&lt;/p&gt;
&lt;p&gt;### Details
IMAP&amp;#39;s `uid-set` and `sequence-set` formats can compress ranges of numbers, for example: `&amp;#34;1,2,3,4,5&amp;#34;` and `&amp;#34;1:5&amp;#34;` both represent the same set.  When `Net::IMAP::ResponseParser` receives `APPENDUID` or `COPYUID` response codes, it expands each `uid-set` into an array of integers.  On a 64 bit system, these arrays will expand to 8 bytes for each number in the set.  A malicious IMAP server may send specially crafted `APPENDUID` or `COPYUID` responses with very large `uid-set` ranges.&lt;/p&gt;
&lt;p&gt;The `Net::IMAP` client parses each server response in a separate thread, as soon as each responses is received from the server.  This attack works even when the client does not handle the `APPENDUID` or `COPYUID` responses.&lt;/p&gt;
&lt;p&gt;Malicious inputs:&lt;/p&gt;
&lt;p&gt;```ruby
# 40 bytes expands to ~1.6GB:
&amp;#34;* OK [COPYUID 1 1:99999999 1:99999999]\r\n&amp;#34;&lt;/p&gt;
&lt;p&gt;# Worst *valid* input scenario (using uint32 max),
# 44 bytes expands to 64GiB:
&amp;#34;* OK [COPYUID 1 1:4294967295 1:4294967295]\r\n&amp;#34;&lt;/p&gt;
&lt;p&gt;# Numbers must be non-zero uint32, but this isn&amp;#39;t validated.  Arrays larger than
# UINT32_MAX can be cre…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7fc5-f82f-cx69</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-25186 — Net::IMAP vulnerable to possible DoS by memory exhaustion</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-25186</link>
      <description>msrc_CVE-2025-25186</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-25186</guid>
    </item>
    <item>
      <title>OESA-2025-1195 — ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1195</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`&amp;amp;apos;s response parser.  At any time while the client is connected, a malicious server can send  can send highly compressed `uid-set` data which is automatically read by the client&amp;amp;apos;s receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.(CVE-2025-25186)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`&amp;amp;apos;s response parser.  At any time while the client is connected, a malicious server can send  can send highly compressed `uid-set` data which is automatically read by the client&amp;amp;apos;s receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.(CVE-2025-25186)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1195</guid>
    </item>
    <item>
      <title>RHSA-2025:10217 — Red Hat Security Advisory: ruby:3.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:10217</link>
      <description>&lt;p&gt;net-imap: Net::IMAP vulnerable to possible DoS by memory exhaustion CGI: Denial of Service in CGI::Cookie.parse uri: userinfo leakage in URI#join, URI#merge and URI#+&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;net-imap: Net::IMAP vulnerable to possible DoS by memory exhaustion CGI: Denial of Service in CGI::Cookie.parse uri: userinfo leakage in URI#join, URI#merge and URI#+&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:10217</guid>
    </item>
    <item>
      <title>RHSA-2025:3906 — Red Hat Security Advisory: Logging for Red Hat OpenShift - 5.9.13</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:3906</link>
      <description>&lt;p&gt;net-imap: Net::IMAP vulnerable to possible DoS by memory exhaustion go-jose: Go JOSE&amp;#39;s Parsing Vulnerable to Denial of Service rack: rubygem-rack: Local File Inclusion in Rack::Static golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;net-imap: Net::IMAP vulnerable to possible DoS by memory exhaustion go-jose: Go JOSE&amp;#39;s Parsing Vulnerable to Denial of Service rack: rubygem-rack: Local File Inclusion in Rack::Static golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:3906</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-25186</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-25186</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: ruby3.2&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`&amp;#39;s response parser.  At any time while the client is connected, a malicious server can send  can send highly compressed `uid-set` data which is automatically read by the client&amp;#39;s receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: ruby3.2&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`&amp;#39;s response parser.  At any time while the client is connected, a malicious server can send  can send highly compressed `uid-set` data which is automatically read by the client&amp;#39;s receiver thread. The response parser uses `Range#to_a` to convert the `uid-set` data into arrays of integers, with no limitation on the expanded size of the ranges. Versions 0.3.8, 0.4.19, 0.5.6, and higher fix this issue. Additional details for proper configuration of fixed versions and backward compatibility are available in the GitHub Security Advisory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-25186</guid>
    </item>
  </channel>
</rss>
