CVE-2026-42246
Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.
- CVSS 4.0
- 7.6 HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-392, CWE-393, CWE-636, CWE-754, CWE-841, CWE-325
- Affected
- ruby-lang/net\
- Source
- security-advisories@github.com
References
- https://github.com/ruby/net-imap/commit/0ede4c40b1523dfeaf95777b2678e54cc0fd9618Patch
- https://github.com/ruby/net-imap/commit/24a4e770b43230286a05aa2a9746cdbb3eb8485ePatch
- https://github.com/ruby/net-imap/commit/97e2488fb5401a1783bddd959dde007d9fbce42cPatch
- https://github.com/ruby/net-imap/commit/f79d35bf5833f186e81044c57c843eda30c873daPatch
- https://github.com/ruby/net-imap/releases/tag/v0.3.10Release Notes
- https://github.com/ruby/net-imap/releases/tag/v0.4.24Release Notes
- https://github.com/ruby/net-imap/releases/tag/v0.5.14Release Notes
- https://github.com/ruby/net-imap/security/advisories/GHSA-vcgp-9326-pqcpMitigation, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:33462
- https://access.redhat.com/errata/RHSA-2026:33512
- https://access.redhat.com/errata/RHSA-2026:33514
- https://access.redhat.com/errata/RHSA-2026:33515
- https://access.redhat.com/errata/RHSA-2026:33540
- https://access.redhat.com/errata/RHSA-2026:33551
- https://access.redhat.com/errata/RHSA-2026:33552
- https://access.redhat.com/errata/RHSA-2026:33565
- https://access.redhat.com/errata/RHSA-2026:33576
- https://access.redhat.com/errata/RHSA-2026:33577
- https://access.redhat.com/errata/RHSA-2026:33630
- https://access.redhat.com/errata/RHSA-2026:33721
- https://access.redhat.com/errata/RHSA-2026:34076
- https://access.redhat.com/errata/RHSA-2026:35834
- https://access.redhat.com/errata/RHSA-2026:35866
- https://access.redhat.com/errata/RHSA-2026:35867
- https://access.redhat.com/errata/RHSA-2026:35895
- https://access.redhat.com/errata/RHSA-2026:36099
- https://access.redhat.com/errata/RHSA-2026:37238
- https://access.redhat.com/errata/RHSA-2026:37397
- https://access.redhat.com/security/cve/CVE-2026-42246
- https://bugzilla.redhat.com/show_bug.cgi?id=2468499
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.