Project

General

Profile

Actions

Bug #21297

closed

Update net-imap for ruby 3.2, 3.3, 3.4

Added by nevans (Nicholas Evans) about 2 months ago. Updated about 1 month ago.

Status:
Closed
Assignee:
-
Target version:
-
[ruby-core:121782]

Description

The bundled net-imap versions are vulnerable to CVE-2025-43857 (GHSA-j3g3-5qv5-52mj). This vulnerability does not affect securely connecting to trusted IMAP servers that are well-behaved. It can affect insecure connections and buggy, untrusted, or compromised servers (for example, connecting to a user supplied hostname).

Fixing the issue requires upgrading to v0.2.5, v0.3.9, v0.4.20, or v0.5.7.

I didn't have a release ready in time to be bundled with the final version of ruby 3.1, so I haven't created a PR for v0.2.5.
v0.4.21 and v0.5.8 are primarily bug fixes, so my PRs for ruby 3.3 and 3.4 upgrade to those versions.

The workaround is to uninstall the vulnerable bundled versions and gem install net-imap.

Security Advisory Links:

Actions

Also available in: Atom PDF

Like0
Like0Like0Like0