Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-87pf-fpwv-p7m7 | net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication |
Sat, 16 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-606 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 11 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 10 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ruby-lang
Ruby-lang net::imap |
|
| Vendors & Products |
Ruby-lang
Ruby-lang net::imap |
Sat, 09 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.14, and 0.6.0 to before 0.6.4, when authenticating a connection with SCRAM-SHA1 or SCRAM-SHA256, a hostile server can perform a computational denial-of-service attack on the client process by sending a big iteration count value. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4. | |
| Title | net-imap: Denial of service via high iteration count for `SCRAM-*` authentication | |
| Weaknesses | CWE-1322 CWE-770 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-11T17:04:42.562Z
Reserved: 2026-04-26T11:53:27.704Z
Link: CVE-2026-42256
Updated: 2026-05-11T17:04:36.128Z
Status : Undergoing Analysis
Published: 2026-05-09T20:16:28.313
Modified: 2026-05-13T15:39:39.350
Link: CVE-2026-42256
OpenCVE Enrichment
Updated: 2026-05-16T02:00:12Z
Github GHSA