PT-2026-36986 · Cpan+1 · Net::Imap+1

·

CVE-2026-42245

·

Published

2026-05-04

·

Updated

2026-07-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Net::IMAP (affected versions not specified)
Description Net::IMAP::ResponseReader exhibits quadratic time complexity when processing large responses containing numerous string literals. A hostile server can send specially crafted responses that force the ResponseReader to rescan the entire growing response buffer for each literal, leading to excessive CPU consumption and a denial of service. This algorithmic complexity allows the issue to bypass max response size protections, as a response can remain below the size limit while still incurring high CPU costs. Because the process retains the Global VM lock during scanning, other threads are significantly impacted.
Recommendations Upgrade to a patched version of net-imap. Avoid connecting to untrusted IMAP servers. When connecting to untrusted servers, reduce max response size to a much smaller value, such as 8KiB, to limit the impact.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:33515
ALSA-2026:33540
ALSA-2026:33565
ALSA-2026:33576
ALSA-2026:33577
CLEANSTART-2026-RG00675
CLEANSTART-2026-UT74115
CVE-2026-42245
ECHO-308F-3B2D-BB3E
GHSA-Q2MW-FVJ9-VVCW
OESA-2026-2578
RHSA-2026:33515
RHSA-2026:33540
RHSA-2026:33551
RHSA-2026:33552
RHSA-2026:33565
RHSA-2026:33576
RHSA-2026:33577
RHSA-2026:33721
RHSA-2026:35895
RHSA-2026:36099
RHSA-2026:38694

Affected Products

Net::Imap
Rocky Linux