CVE-2026-42245: net-imap: Quadratic complexity when reading response literals
Telemetry drift only. No threshold crossed and no authority ruling changed.
CVE record loaded 2026-09-20.
What to do now held facts and links
- Upgrade to the fixed version for your release line, or later: net\ 0.4.24; net\ 0.5.14; net\ 0.6.4 upper bounds of the CVE record's affected ranges
- Later advisories still cover the fixes above and name higher ones: net-imap 0.6.4.1 (CVE-2026-47240), 0.6.4.1 (CVE-2026-47241), 0.6.4.1 (CVE-2026-47242) OSV advisories
- Record your decision, dated and frozen with today's evidence: patch by a date · mitigated by a compensating control · deferred · accepted the risk · not affected
- Check your version against the ranges this record publishes.
What it is stated by the CNA
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client's CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.
- weakness
- CWE-407: Inefficient Algorithmic Complexity
- affected
- ruby net-imap
- versions
- ruby net-imap < 0.4.24; ruby net-imap >= 0.5.0, < 0.5.14; ruby net-imap >= 0.6.0, < 0.6.4
- published ranges
- ruby-lang net\ < 0.4.24; ruby-lang net\ >= 0.5.0 < 0.5.14; ruby-lang net\ >= 0.6.0 < 0.6.4
- first unaffected version, by branch
- net\ 0.4.24; net\ 0.5.14; net\ 0.6.4
- fixed by package (from OSV advisories)
- net-imap (RubyGems): 0.4.24; 0.5.14; 0.6.4 GHSA-q2mw-fvj9-vvcw
- later fixes (from OSV advisories)
- net-imap 0.4.24 is inside a range CVE-2026-47240 (GHSA-8p34-64r3-mwg8) lists as affected. That advisory is fixed in 0.5.15.net-imap 0.4.24 is inside a range CVE-2026-47241 (GHSA-c4fp-cxrr-mj66) lists as affected. That advisory is fixed in 0.5.15.net-imap 0.4.24 is inside a range CVE-2026-47242 (GHSA-46q3-7gv7-qmgg) lists as affected. That advisory is fixed in 0.5.15.net-imap 0.5.14 is inside a range CVE-2026-47240 (GHSA-8p34-64r3-mwg8) lists as affected. That advisory is fixed in 0.5.15.net-imap 0.5.14 is inside a range CVE-2026-47241 (GHSA-c4fp-cxrr-mj66) lists as affected. That advisory is fixed in 0.5.15.net-imap 0.5.14 is inside a range CVE-2026-47242 (GHSA-46q3-7gv7-qmgg) lists as affected. That advisory is fixed in 0.5.15.
- severity
- 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
- assigned by
- GitHub_M
- published
- 2026-05-09
check us github.com github.com github.com github.com
Exploit code held, dated
- exploit code
- None held in the PoC-in-GitHub feed. A public repository changes this brief.
What moved held, dated
| date | EPSS | event |
|---|---|---|
| 10 May 2026 | 0.00062 | |
| 15 May 2026 | 0.00082 | |
| 19 May 2026 | 0.00086 | |
| 10 Jun 2026 | 0.00093 | |
| 15 Jun 2026 | 0.0041 | scoring model v2026.06.15 |
| 28 Sep 2026 | 0.007 |
6 observations held. A step marked with a scoring model moved because the measurement was replaced, not because the vulnerability changed.
Outside the record researched, cited
This section reads the record's references and adds cited findings from outside it. It needs an account. Everything above is held facts and is complete without it.
What would change this brief held, dated
- CISA KEV
- Not listed in the catalogue we hold. A listing changes this brief.
- exploit probability
- 0.01 on 2026-09-28 (FIRST's EPSS, a probability and not evidence of exploitation). Next band line: 10% (0.10). Crossing a line changes this brief.
- fix
- Held: net\ 0.4.24; net\ 0.5.14; net\ 0.6.4 (CVE record, loaded 2026-09-20). A newer fix from the CNA or OSV changes this brief.
How to check this
Every value above is held with two dates: when it was true upstream (as_of) and when we recorded it (tx_from). Re-derive the exploit probability as it stood on any date:
SELECT value, source, source_version, as_of, tx_from
FROM volatile_valid_as_of('CVE-2026-42245', '2026-10-03T23:59:59.999999Z', now());Identity above is quoted from the CVE Program record, corpus cvelistv5_20260920, recorded 30 Sep 2026.