Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Two critical vulnerabilities were discovered in Ruby's Net::IMAP library affecting Ubuntu 18.04 and 16.04 LTS. CVE-2026-42246 allows remote attackers to perform machine-in-the-middle attacks by bypassing TLS encryption. CVE-2026-42257 enables attackers to inject arbitrary IMAP commands due to improp...
Recent updates for Oracle Linux address critical vulnerabilities in Ruby affecting versions 2.5, 3.3, and 4.0. Key issues include a code execution flaw (CVE-2026-41316) and denial of service vulnerabilities (CVE-2026-42245, CVE-2026-33210) that could be exploited via crafted IMAP responses and forma...
On October 1, 2026, Oracle released security updates for Ruby in Oracle Linux 9 and 10, addressing multiple memory exhaustion vulnerabilities. The most significant flaw, CVE-2026-80212, affects Ruby versions 3.0.7 and 4.0.6, allowing for potential denial of service through unknown DNS resource types...