<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:05:09 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:33512 — Important: ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:33512</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: ruby, AlmaLinux:9: ruby-default-gems, AlmaLinux:9: ruby-devel, AlmaLinux:9: ruby-doc, AlmaLinux:9: ruby-libs, AlmaLinux:9: rubygem-bigdecimal, AlmaLinux:9: rubygem-bundler, AlmaLinux:9: rubygem-io-console, AlmaLinux:9: rubygem-irb, AlmaLinux:9: rubygem-json and 12 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258)
  * net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: ruby, AlmaLinux:9: ruby-default-gems, AlmaLinux:9: ruby-devel, AlmaLinux:9: ruby-doc, AlmaLinux:9: ruby-libs, AlmaLinux:9: rubygem-bigdecimal, AlmaLinux:9: rubygem-bundler, AlmaLinux:9: rubygem-io-console, AlmaLinux:9: rubygem-irb, AlmaLinux:9: rubygem-json and 12 more&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258)
  * net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:33512</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-42258</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-42258</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: ruby-net-imap, Alpaquita:stream: ruby-net-imap&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: ruby-net-imap, Alpaquita:stream: ruby-net-imap&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-42258</guid>
    </item>
    <item>
      <title>BREW-imap-backup-CVE-2026-42258 — net-imap vulnerable to command Injection via unvalidated Symbol inputs</title>
      <link>https://cve.radiocsirt.org/vuln/brew-imap-backup-cve-2026-42258</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: imap-backup&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Symbol arguments represent IMAP &amp;#34;system flags&amp;#34;, which are formatted as &amp;#34;atoms&amp;#34; (with no quoting) with a `&amp;#34;\&amp;#34;` prefix.  Vulnerable versions of Net::IMAP sends the symbol name directly to the socket, with no validation.&lt;/p&gt;
&lt;p&gt;Because the Symbol input is unvalidated, it could contain invalid `flag` characters, including `SP` and `CRLF`, which could be used to finish the current command and inject new commands.&lt;/p&gt;
&lt;p&gt;Although IMAP `flag` arguments are only valid input for a few IMAP commands, most Net::IMAP commands use generic argument handling, and will allow Symbol (`flag`) inputs.&lt;/p&gt;
&lt;p&gt;Note also that the list of valid symbol inputs should be restricted to an enumerated set of standard RFC defined flag types, which have each been given specific defined semantics.  Any user-provided values outside of that list of standard &amp;#34;system flags&amp;#34; needs to use the IMAP `keyword` syntax, which are sent as atoms, i.e: string inputs. Under no circumstances should `#to_sym` ever be called on unvetted user-provided input: that will always be a bug in the calling code for the simple reason that `user_input_atom` is  as `\user_input_atom`.&lt;/p&gt;
&lt;p&gt;For forward compatibility with future IMAP extentions, Net::IMAP, does not restrict flag inputs to an enumerated list.  That is the responsibility of the calling application code, which knows which flag semantics…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: imap-backup&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Symbol arguments represent IMAP &amp;#34;system flags&amp;#34;, which are formatted as &amp;#34;atoms&amp;#34; (with no quoting) with a `&amp;#34;\&amp;#34;` prefix.  Vulnerable versions of Net::IMAP sends the symbol name directly to the socket, with no validation.&lt;/p&gt;
&lt;p&gt;Because the Symbol input is unvalidated, it could contain invalid `flag` characters, including `SP` and `CRLF`, which could be used to finish the current command and inject new commands.&lt;/p&gt;
&lt;p&gt;Although IMAP `flag` arguments are only valid input for a few IMAP commands, most Net::IMAP commands use generic argument handling, and will allow Symbol (`flag`) inputs.&lt;/p&gt;
&lt;p&gt;Note also that the list of valid symbol inputs should be restricted to an enumerated set of standard RFC defined flag types, which have each been given specific defined semantics.  Any user-provided values outside of that list of standard &amp;#34;system flags&amp;#34; needs to use the IMAP `keyword` syntax, which are sent as atoms, i.e: string inputs. Under no circumstances should `#to_sym` ever be called on unvetted user-provided input: that will always be a bug in the calling code for the simple reason that `user_input_atom` is  as `\user_input_atom`.&lt;/p&gt;
&lt;p&gt;For forward compatibility with future IMAP extentions, Net::IMAP, does not restrict flag inputs to an enumerated list.  That is the responsibility of the calling application code, which knows which flag semantics…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-imap-backup-cve-2026-42258</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</link>
      <description>certfr-2026-avi-0958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-RG00675 — Security fixes for CVE-2026-33637, CVE-2026-42245, CVE-2026-42246, CVE-2026-42256, CVE-2026-42257, CVE-2026-42258, ghsa…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-rg00675</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby-fluentd-1.19&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the ruby-fluentd-1.19 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: ruby-fluentd-1.19&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the ruby-fluentd-1.19 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-rg00675</guid>
    </item>
    <item>
      <title>EUVD-2026-362269</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362269</link>
      <description>EUVD-2026-362269</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362269</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42258</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42258</link>
      <description>&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42258</guid>
    </item>
    <item>
      <title>GHSA-75xq-5h9v-w6px — net-imap vulnerable to command Injection via unvalidated Symbol inputs</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-75xq-5h9v-w6px</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: net-imap&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Symbol arguments represent IMAP &amp;#34;system flags&amp;#34;, which are formatted as &amp;#34;atoms&amp;#34; (with no quoting) with a `&amp;#34;\&amp;#34;` prefix.  Vulnerable versions of Net::IMAP sends the symbol name directly to the socket, with no validation.&lt;/p&gt;
&lt;p&gt;Because the Symbol input is unvalidated, it could contain invalid `flag` characters, including `SP` and `CRLF`, which could be used to finish the current command and inject new commands.&lt;/p&gt;
&lt;p&gt;Although IMAP `flag` arguments are only valid input for a few IMAP commands, most Net::IMAP commands use generic argument handling, and will allow Symbol (`flag`) inputs.&lt;/p&gt;
&lt;p&gt;Note also that the list of valid symbol inputs should be restricted to an enumerated set of standard RFC defined flag types, which have each been given specific defined semantics.  Any user-provided values outside of that list of standard &amp;#34;system flags&amp;#34; needs to use the IMAP `keyword` syntax, which are sent as atoms, i.e: string inputs. Under no circumstances should `#to_sym` ever be called on unvetted user-provided input: that will always be a bug in the calling code for the simple reason that `user_input_atom` is  as `\user_input_atom`.&lt;/p&gt;
&lt;p&gt;For forward compatibility with future IMAP extentions, Net::IMAP, does not restrict flag inputs to an enumerated list.  That is the responsibility of the calling application code, which knows which flag semantics…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; RubyGems: net-imap&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Symbol arguments represent IMAP &amp;#34;system flags&amp;#34;, which are formatted as &amp;#34;atoms&amp;#34; (with no quoting) with a `&amp;#34;\&amp;#34;` prefix.  Vulnerable versions of Net::IMAP sends the symbol name directly to the socket, with no validation.&lt;/p&gt;
&lt;p&gt;Because the Symbol input is unvalidated, it could contain invalid `flag` characters, including `SP` and `CRLF`, which could be used to finish the current command and inject new commands.&lt;/p&gt;
&lt;p&gt;Although IMAP `flag` arguments are only valid input for a few IMAP commands, most Net::IMAP commands use generic argument handling, and will allow Symbol (`flag`) inputs.&lt;/p&gt;
&lt;p&gt;Note also that the list of valid symbol inputs should be restricted to an enumerated set of standard RFC defined flag types, which have each been given specific defined semantics.  Any user-provided values outside of that list of standard &amp;#34;system flags&amp;#34; needs to use the IMAP `keyword` syntax, which are sent as atoms, i.e: string inputs. Under no circumstances should `#to_sym` ever be called on unvetted user-provided input: that will always be a bug in the calling code for the simple reason that `user_input_atom` is  as `\user_input_atom`.&lt;/p&gt;
&lt;p&gt;For forward compatibility with future IMAP extentions, Net::IMAP, does not restrict flag inputs to an enumerated list.  That is the responsibility of the calling application code, which knows which flag semantics…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-75xq-5h9v-w6px</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-42258 — net-imap: Command Injection via unvalidated Symbol inputs</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42258</link>
      <description>msrc_CVE-2026-42258</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-42258</guid>
    </item>
    <item>
      <title>OESA-2026-2578 — ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2578</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: ruby, openEuler:22.03-LTS-SP4: ruby, openEuler:24.03-LTS-SP1: ruby, openEuler:24.03-LTS-SP3: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client&amp;amp;apos;s CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.(CVE-2026-42245)&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return &amp;amp;quot;successfully&amp;amp;quot;, without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.(CVE-2026-42246)&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.(CVE-2026…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: ruby, openEuler:22.03-LTS-SP4: ruby, openEuler:24.03-LTS-SP1: ruby, openEuler:24.03-LTS-SP3: ruby&lt;/p&gt;
&lt;p&gt;Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client&amp;amp;apos;s CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.(CVE-2026-42245)&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return &amp;amp;quot;successfully&amp;amp;quot;, without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.(CVE-2026-42246)&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.(CVE-2026…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2578</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21878-1 — Security update for ruby3.4</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21878-1</link>
      <description>&lt;p&gt;Security update for ruby3.4&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ruby3.4&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21878-1</guid>
    </item>
    <item>
      <title>RHSA-2026:33630 — Red Hat Security Advisory: ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:33630</link>
      <description>&lt;p&gt;net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:33630</guid>
    </item>
    <item>
      <title>RLSA-2026:33512 — Important: ruby security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:33512</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: ruby&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258)&lt;/p&gt;
&lt;p&gt;* net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: ruby&lt;/p&gt;
&lt;p&gt;Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments (CVE-2026-42258)&lt;/p&gt;
&lt;p&gt;* net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS (CVE-2026-42246)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:33512</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-42258</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42258</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:18.04:LTS: jruby, Ubuntu:Pro:20.04:LTS: ruby2.7, Ubuntu:20.04:LTS: jruby, Ubuntu:22.04:LTS: ruby3.0, Ubuntu:24.04:LTS: jruby, Ubuntu:24.04:LTS: ruby3.2 and 4 more&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jruby, Ubuntu:Pro:16.04:LTS: ruby2.3, Ubuntu:16.04:LTS: jruby, Ubuntu:Pro:18.04:LTS: ruby2.5, Ubuntu:18.04:LTS: jruby, Ubuntu:Pro:20.04:LTS: ruby2.7, Ubuntu:20.04:LTS: jruby, Ubuntu:22.04:LTS: ruby3.0, Ubuntu:24.04:LTS: jruby, Ubuntu:24.04:LTS: ruby3.2 and 4 more&lt;/p&gt;
&lt;p&gt;Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42258</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2117 — HCL BigFix Compliance (Ruby): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2117</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix Compliance ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in HCL BigFix Compliance ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2117</guid>
    </item>
  </channel>
</rss>
