PT-2026-37183 · Cpan+3 · Net::Imap+3

·

CVE-2026-42246

·

Published

2025-06-29

·

Updated

2026-07-10

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Net::IMAP versions prior to 0.3.10 Net::IMAP versions prior to 0.4.24 Net::IMAP versions prior to 0.5.14 Net::IMAP versions prior to 0.6.4
Description A man-in-the-middle attacker can cause the starttls() function to return successfully without actually establishing a TLS connection. This occurs when an attacker injects a tagged OK response with a predictable tag before the client finishes sending the command, causing the command to complete before the response handler is registered. This results in a STARTTLS stripping attack, where the socket remains unencrypted, leading to the cleartext transmission of sensitive information.
Recommendations Update to version 0.3.10. Update to version 0.4.24. Update to version 0.5.14. Update to version 0.6.4. Connect to an implicit TLS port instead of using STARTTLS with a cleartext port. Explicitly verify that tls verified? is true before using the connection after calling starttls().

Exploit

Fix

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:33512
ALSA-2026:33514
ALSA-2026:33515
ALSA-2026:33540
ALSA-2026:33565
ALSA-2026:33576
ALSA-2026:33577
CVE-2026-42246
ECHO-EEF9-A5B3-0486
GHSA-VCGP-9326-PQCP
OESA-2026-2578
RHSA-2026:33462
RHSA-2026:33512
RHSA-2026:33514
RHSA-2026:33515
RHSA-2026:33540
RHSA-2026:33551
RHSA-2026:33552
RHSA-2026:33565
RHSA-2026:33576
RHSA-2026:33577
RHSA-2026:33630
RHSA-2026:33721
RHSA-2026:34076
RHSA-2026:35834
RHSA-2026:35866
RHSA-2026:35867
RHSA-2026:35895
RHSA-2026:36099
RHSA-2026:37397
USN-8431-1
USN-8478-1

Affected Products

Linuxmint
Net::Imap
Rocky Linux
Ubuntu