Project

General

Profile

Actions

Bug #21297

open

Update net-imap for ruby 3.2, 3.3, 3.4

Added by nevans (Nicholas Evans) 6 days ago. Updated 6 days ago.

Status:
Open
Assignee:
-
Target version:
-
[ruby-core:121782]

Description

The bundled net-imap versions are vulnerable to CVE-2025-43857 (GHSA-j3g3-5qv5-52mj). This vulnerability does not affect securely connecting to trusted IMAP servers that are well-behaved. It can affect insecure connections and buggy, untrusted, or compromised servers (for example, connecting to a user supplied hostname).

Fixing the issue requires upgrading to v0.2.5, v0.3.9, v0.4.20, or v0.5.7.

I didn't have a release ready in time to be bundled with the final version of ruby 3.1, so I haven't created a PR for v0.2.5.
v0.4.21 and v0.5.8 are primarily bug fixes, so my PRs for ruby 3.3 and 3.4 upgrade to those versions.

The workaround is to uninstall the vulnerable bundled versions and gem install net-imap.

Security Advisory Links:

Actions #1

Updated by nevans (Nicholas Evans) 6 days ago

  • Description updated (diff)
Actions

Also available in: Atom PDF

Like0
Like0