Junglewise Threat Intelligence

CVE-2026-47240: Ruby Net::IMAP command injection via non-synchronizing literals

CVE-2026-47240 · Severity: medium · CVSS 4 · Published 2026-06-22

Vendors: Ruby.

Executive brief

The Ruby net-imap library, which allows applications to communicate with email servers, contains a flaw in how it handles certain data commands. If an application using this library passes unvalidated user input to specific email search or fetch functions, an attacker could inject unauthorized commands. This could allow an attacker to perform unintended actions on the email server, such as deleting mailboxes or modifying folder structures, depending on the server's configuration.

Technical details

A CRLF injection vulnerability exists in Net::IMAP's handling of 'raw data' arguments for commands including #search, #sort, #thread, and #fetch. The root cause is the library's failure to validate server support for non-synchronizing literals (LITERAL+, LITERAL-, or IMAP4rev2) before sending them. If a server does not support these literals, it may interpret the '+}\r\n' sequence as the end of a malformed command and treat the subsequent literal content as new, pipelined IMAP commands. An attacker providing unvalidated input to these methods can execute arbitrary IMAP commands, such as DELETE. The vulnerability is fixed in versions 0.6.4.1 and 0.5.15.

Affected products

  • ruby net-imap >= 0.6.0, < 0.6.4.1; < 0.5.15

Timeline

  • 2026-06-09: advisory: GitHub advisory GHSA-8p34-64r3-mwg8 published
  • 2026-06-22: disclosed: CVE-2026-47240 published to NVD

References