Junglewise Threat Intelligence

CVE-2026-42245: Ruby Net::IMAP denial of service in ResponseReader

CVE-2026-42245 · Severity: high · CVSS 7.5 · Published 2026-05-09

Vendors: Ruby.

Executive brief

The Net::IMAP library, used by Ruby applications to communicate with email servers, is vulnerable to a denial-of-service attack. A malicious or compromised email server can send specially crafted responses that cause the Ruby application to consume excessive CPU resources. This can lead to the application becoming unresponsive, potentially disrupting email processing services.

Technical details

The vulnerability exists in the Net::IMAP::ResponseReader component of the Ruby Net::IMAP library. It is caused by inefficient algorithmic complexity (CWE-407) when parsing large IMAP server responses that contain a high volume of string literals, leading to quadratic time complexity. A remote attacker controlling a hostile IMAP server can exploit this by sending a crafted response to a client, exhausting the client's CPU and causing a denial of service. The issue is fixed in versions 0.4.24, 0.5.14, and 0.6.4 by optimizing the response reader performance.

Affected products

  • Ruby Net::IMAP < 0.4.24, 0.5.0 to < 0.5.14, 0.6.0 to < 0.6.4

Timeline

  • 2026-05-09: disclosed
  • 2026-04-23: patched: Release of versions 0.4.24 and 0.5.14

References