CVE-2026-42246High· 7.4▾ TwilightNet::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without s…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.
net::imap < 0.3.10net::imap >= 0.4.0, < 0.4.24net::imap >= 0.5.0, < 0.5.14net::imap >= 0.6.0, < 0.6.4Upgrade past the affected range:
net::imap 0.6.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-33210Critical· 9.1Ruby JSON is a JSON implementation for Ruby
CVE-2026-73549Medium· 5.3Envoy is an open source edge and service proxy designed for cloud-native applications
CVE-2026-48974Medium· 5.4HomeBox is a home inventory and organization system
CVE-2026-77560High· 8.1Tinyauth is an authentication and authorization server
CVE-2026-94105Medium· 5.3NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that allows unauthenticated attackers to disable password recovery by supplying an invalid code parameter
CVE-2026-73421NoneNextAuth.js provides authentication for Next.js