PT-2026-48342 · Cpan+2 · Net::Imap+2

·

CVE-2026-47242

·

Published

2026-06-09

·

Updated

2026-08-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Net::IMAP versions prior to 0.5.15 Net::IMAP versions prior to 0.6.5
Description The Net::IMAP#id and Net::IMAP#enable functions do not properly validate their arguments. When Net::IMAP#id is called with a hash argument, it fails to prohibit CRLF (Carriage Return Line Feed) sequences, which are special characters used to indicate the end of a line. Similarly, Net::IMAP#enable does not validate arguments as valid atoms, sending the #to s value verbatim. An attacker providing untrusted input to these commands could inject arbitrary IMAP commands, such as deleting a mailbox.
Recommendations Update to version 0.5.15. Update to version 0.6.5. Avoid using untrusted inputs for Net::IMAP#enable arguments. Ensure client ID field values do not contain CR or LF bytes or implement validation to prohibit these characters.

Exploit

Fix

DoS

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:50827
ALSA-2026:50828
AZL-91284
CVE-2026-47242
ECHO-D8B1-4397-2A2E
GHSA-46Q3-7GV7-QMGG
OESA-2026-3536
RHSA-2026:33551
RHSA-2026:33721
RHSA-2026:34293
RHSA-2026:40380
RHSA-2026:54391
RHSA-2026:54393
RHSA-2026:54416
SUSE-SU-2026:3090-1

Affected Products

Net::Imap
Red Os
Rocky Linux