CVE-2026-42245Disclosure(ruby-lang / net\)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client's CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-407

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • net\

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
net\

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-05: 1Mentions · 2026-05-09: 1Mentions · 2026-05-10: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-09: 105-0505-0905-10
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-051
Disclosure1
2026-05-091
Disclosure1
2026-05-101
General1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-42245 Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has … https://www.cve.org/CVERecord?id=CVE-2026-42245

    Post summary

    A brief notice of CVE‑2026‑42245 affecting Ruby Net::IMAP with a link to its CVE record; no details on exploitation, mitigation, or technical specifics are given.

    0000089
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42245 Denial of Service via Quadratic Time Complexity in Net::IMAP Resp... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42245 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE-2026-42245, a Denial‑of‑Service vulnerability caused by quadratic time complexity in Net::IMAP response handling, linking to details but offering no evidence of exploitation or remediation.

    0000060
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔵 Net::IMAP (Ruby), Quadratic Complexity, #CVE-2026-42245 (Low) https://dailycve.com/netimap-ruby-quadratic-complexity-cve-2026-42245-low/

    Post summary

    The tweet announces the discovery of CVE-2026-42245 in Ruby's Net::IMAP module, describing it as a quadratic‑complexity vulnerability of low severity.

    0000030
    191 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appruby-langnet\\--

Explore more