Skip to content

CVE-2026-42258

CVE

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
July 6, 2026
Last Seen
October 1, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Recent updates for Oracle Linux address critical vulnerabilities in Ruby affecting versions 2.5, 3.3, and 4.0. Key issues include a code execution flaw (CVE-2026-41316) and denial of service vulnerabilities (CVE-2026-42245, CVE-2026-33210) that could be exploited via crafted IMAP responses and forma...

Two critical vulnerabilities were discovered in Ruby affecting the Net::IMAP client and Zlib::GzipReader. CVE-2026-42258 allows remote attackers to inject arbitrary IMAP commands via CRLF sequences, while CVE-2026-27820 can lead to a buffer overflow through crafted gzip streams. These vulnerabilitie...

On October 1, 2026, Oracle released security updates for Ruby in Oracle Linux 9 and 10, addressing multiple memory exhaustion vulnerabilities. The most significant flaw, CVE-2026-80212, affects Ruby versions 3.0.7 and 4.0.6, allowing for potential denial of service through unknown DNS resource types...

Public Exploits

Checking GitHub for proof-of-concept code…