CVE-2026-42256General(ruby-lang / net\)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.14, and 0.6.0 to before 0.6.4, when authenticating a connection with SCRAM-SHA1 or SCRAM-SHA256, a hostile server can perform a computational denial-of-service attack on the client process by sending a big iteration count value. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770CWE-1322

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • net\

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
net\

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-05: 1Mentions · 2026-05-09: 1Mentions · 2026-05-10: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-09: 105-0505-0905-10
Signal classification1 categories
General
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-42256 Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.14, and 0.6.0 to … https://www.cve.org/CVERecord?id=CVE-2026-42256

    Post summary

    The text merely cites a CVE identifier and affected Ruby Net::IMAP version ranges, providing no further detail on exploitation, patches, or technical content.

    0000094
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42256 Denial of Service in Net::IMAP SCRAM Authentication via Iteration Count https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42256

    Post summary

    The text provides a technical description of CVE-2026-42256 as a Denial of Service flaw in Net::IMAP SCRAM authentication tied to iteration count handling, but it lacks any PoC, exploit code, active exploitation, patch, or false‑positive discussion.

    0000053
    4.0K followersView on X
  • DailyCVE@dailycve
    General

    🟠 Ruby net-imap, Denial of Service, #CVE-2026-42256 (Moderate) https://dailycve.com/ruby-net-imap-denial-of-service-cve-2026-42256-moderate/

    Post summary

    The text references a Ruby net-imap denial of service CVE (2026-42256) with minimal detail, providing only its identifier and the vulnerability type.

    0000033
    191 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appruby-langnet\\--

Explore more