Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
Description
Several Net::IMAP commands accept a "raw data" argument that is sent verbatim after validation to prevent command injection. However, if a server does not support non-synchronizing literals, it may still be possible to inject arbitrary IMAP commands inside non-synchronizing literals.
Details
Raw data arguments support embedded literal values, both synchronizing and non-synchronizing. Non-synchronizing literals can only be safely sent when the server advertises any of the LITERAL+, LITERAL-, or IMAP4rev2 capabilities. But raw data arguments do not verify server support for non-synchronizing literals prior to sending.
Servers without support for non-synchronizing literals could handle them in several different ways: If a server sees a "}\r\n" byte sequence but can't parse the literal bytesize, it _may_ cautiously decide to close the connection, blocking any command injection attacks. However, a server without support for non-synchronizing literals may instead interpret the "+}\r\n" as the end of a malformed command line and respond with a tagged BAD. In that case, the contents of the literal will be interpreted as one or more new pipelined commands, allowing a CRLF command injection attack to succeed.
This affects the following commands' string arguments: * criteria for #search and #uid_search * search_keys for #sort, #thread, #uid_sort, and #uid_thread * attr for #fetch and #uid_fetch
Prior to net-imap v0.6.4, v0.5.14, and v0.4.24, raw data arguments were not validated in _any_ way, so they were also vulnerable to this attack. See CVE-2026-42257 (GHSA-hm49-wcqc-g2xg).
Impact
Fortunately, LITERAL- is supported by most modern IMAP servers. Even without support for non-synchronizing literals, cautious servers may handle invalid literal bytesize by closing the connection . However, servers which handle a non-synchronizing literal just like any other malformed command will enable this vulnerability.
If a developer passes an unvalidated user-controlled input for one of these method arguments, an attacker can append CRLF sequence followed by a new IMAP command (like DELETE mailbox). Although this does not directly enable data exfiltration, it could be combined with other attack vectors or knowledge of the target system's attributes, e.g.: shared mail folders or the application's installed response handlers.
Mitigation
Update to a version of net-imap which validates server support for non-synchronizing literals before sending them.
If upgrading net-imap is not possible: * Explicitly validate user-controlled inputs to prevent embedded non-synchronizing literals unless the server supports them. * For a simpler, more cautious approach: all embedded literals can be unconditionally prohibited, by checking that string inputs do not contain any CR or LF bytes. * Verify that the server advertises any of the LITERAL+, LITERAL-, or IMAP4rev2 capabilities before using untrusted string inputs for the affected "raw data" arguments.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
net-imapRubyGems | >= 0.6.0, < 0.6.4.1 | 0.6.4.1 |
net-imapRubyGems | < 0.5.15 | 0.5.15 |
Affected products
45- osv-coords44 versionspkg:apk/chainguard/gitlab-rails-ce-18.11pkg:apk/chainguard/gitlab-rails-ce-18.9pkg:apk/chainguard/gitlab-rails-ce-19.0pkg:apk/chainguard/gitlab-rails-ce-fips-18.10pkg:apk/chainguard/gitlab-rails-ce-fips-18.11pkg:apk/chainguard/kube-fluentd-operatorpkg:apk/chainguard/logstash-8.19pkg:apk/chainguard/logstash-8.19-iamguarded-compatpkg:apk/chainguard/logstash-8.19-with-output-opensearchpkg:apk/chainguard/logstash-9.3pkg:apk/chainguard/logstash-9.3-iamguarded-compatpkg:apk/chainguard/logstash-9.4pkg:apk/chainguard/logstash-9.4-iamguarded-compatpkg:apk/chainguard/logstash-fips-9.4pkg:apk/chainguard/logstash-fips-9.4-iamguarded-compatpkg:apk/chainguard/ruby3.2-kube-logging-operator-fluentd-outputspkg:apk/chainguard/ruby3.2-rails-7.2pkg:apk/chainguard/ruby3.2-rails-8.0pkg:apk/chainguard/ruby3.2-rails-8.1pkg:apk/chainguard/ruby3.3-rails-7.2pkg:apk/chainguard/ruby3.3-rails-8.0pkg:apk/chainguard/ruby3.3-rails-8.1pkg:apk/chainguard/ruby3.4-kube-logging-operator-fluentd-outputspkg:apk/chainguard/ruby3.4-rails-7.2pkg:apk/chainguard/ruby3.4-rails-8.0pkg:apk/chainguard/ruby3.4-rails-8.1pkg:apk/chainguard/ruby4.0-rails-7.2pkg:apk/chainguard/ruby4.0-rails-8.0pkg:apk/chainguard/ruby4.0-rails-8.1pkg:apk/chainguard/trufflerubypkg:apk/wolfi/kube-fluentd-operatorpkg:apk/wolfi/logstash-9.3pkg:apk/wolfi/logstash-9.3-iamguarded-compatpkg:apk/wolfi/logstash-9.4pkg:apk/wolfi/logstash-9.4-iamguarded-compatpkg:apk/wolfi/ruby3.2-kube-logging-operator-fluentd-outputspkg:apk/wolfi/ruby3.2-rails-8.0pkg:apk/wolfi/ruby3.2-rails-8.1pkg:apk/wolfi/ruby3.3-rails-8.0pkg:apk/wolfi/ruby3.3-rails-8.1pkg:apk/wolfi/ruby3.4-kube-logging-operator-fluentd-outputspkg:apk/wolfi/ruby3.4-rails-8.0pkg:apk/wolfi/ruby3.4-rails-8.1pkg:apk/wolfi/ruby4.0-rails-8.1
< 18.11.5-r0+ 43 more
- (no CPE)range: < 18.11.5-r0
- (no CPE)range: < 18.9.8-r3
- (no CPE)range: < 19.0.2-r0
- (no CPE)range: < 18.10.8-r2
- (no CPE)range: < 18.11.5-r0
- (no CPE)range: < 1.18.2-r70
- (no CPE)range: < 8.19.16-r1
- (no CPE)range: < 8.19.16-r1
- (no CPE)range: < 8.19.16-r1
- (no CPE)range: < 9.3.6-r0
- (no CPE)range: < 9.3.6-r0
- (no CPE)range: < 9.4.2-r3
- (no CPE)range: < 9.4.2-r3
- (no CPE)range: < 9.4.2-r2
- (no CPE)range: < 9.4.2-r2
- (no CPE)range: < 6.6.0-r2
- (no CPE)range: < 7.2.3.1-r3
- (no CPE)range: < 8.0.5-r2
- (no CPE)range: < 8.1.3-r5
- (no CPE)range: < 7.2.3.1-r5
- (no CPE)range: < 8.0.5-r5
- (no CPE)range: < 8.1.3-r6
- (no CPE)range: < 6.6.0-r2
- (no CPE)range: < 7.2.3.1-r4
- (no CPE)range: < 8.0.5-r3
- (no CPE)range: < 8.1.3-r6
- (no CPE)range: < 7.2.3.1-r4
- (no CPE)range: < 8.0.5-r4
- (no CPE)range: < 8.1.3-r6
- (no CPE)range: < 34.0.1-r2
- (no CPE)range: < 1.18.2-r70
- (no CPE)range: < 9.3.6-r0
- (no CPE)range: < 9.3.6-r0
- (no CPE)range: < 9.4.2-r3
- (no CPE)range: < 9.4.2-r3
- (no CPE)range: < 6.6.0-r2
- (no CPE)range: < 8.0.5-r2
- (no CPE)range: < 8.1.3-r5
- (no CPE)range: < 8.0.5-r5
- (no CPE)range: < 8.1.3-r6
- (no CPE)range: < 6.6.0-r2
- (no CPE)range: < 8.0.5-r3
- (no CPE)range: < 8.1.3-r6
- (no CPE)range: < 8.1.3-r6
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.