All 7 CVE vulnerabilities found in net-imap, with AI-generated Chinese analysis, references, and POCs.
Vendor: ruby
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-42258 | net-imap: Command Injection via unvalidated Symbol inputs CWE-77 | 9.4AI | CriticalAI | 2026-05-09 |
| CVE-2026-42257 | net-imap: Command Injection via "raw" arguments to multiple commands CWE-93 | 6.5AI | MediumAI | 2026-05-09 |
| CVE-2026-42256 | net-imap: Denial of service via high iteration count for `SCRAM-*` authentication CWE-1322 | 6.5AI | MediumAI | 2026-05-09 |
| CVE-2026-42245 | net-imap: Quadratic complexity when reading response literals CWE-407 | 7.5AI | HighAI | 2026-05-09 |
| CVE-2026-42246 | net-imap vulnerable to STARTTLS stripping via invalid response timing CWE-392 | 5.9AI | MediumAI | 2026-05-09 |
| CVE-2025-43857 | net-imap rubygem vulnerable to possible DoS by memory exhaustion CWE-400 | 7.5AI | HighAI | 2025-04-28 |
| CVE-2025-25186 | Net::IMAP vulnerable to possible DoS by memory exhaustion CWE-400 | 6.5 | Medium | 2025-02-10 |
All 7 known CVE vulnerabilities affecting net-imap with full Chinese analysis, references, and POCs where available.