Skip to content

[CVE-2026-42257] Bump net-imap to 0.5.15 - #461

Merged
Jan-Kazlouski-elastic merged 2 commits into
mainfrom
jan-kazlouski/15476-cve-2026-42257-fix
Aug 4, 2026
Merged

[CVE-2026-42257] Bump net-imap to 0.5.15#461
Jan-Kazlouski-elastic merged 2 commits into
mainfrom
jan-kazlouski/15476-cve-2026-42257-fix

Conversation

@Jan-Kazlouski-elastic

Copy link
Copy Markdown
Contributor

Part of https://github.com/elastic/search-team/issues/15476

Also covers:

Resolves CVE-2026-42257 (critical) — IMAP command injection via CRLF in unvalidated input. Fixed in net-imap 0.5.15 (also clears CVE-2026-42245 / 42258 / 47240 / 47242 / 47241).

Changes

  • Gemfile / Gemfile.lock: pin net-imap 0.3.100.5.15
  • Dockerfile / Dockerfile.wolfi: comment update for the new pin
  • NOTICE.txt: regenerated

Testing

  • Full make test: 690 examples, 0 failures
  • Scanner A/B (all 6 CVEs):

Scanner A/B (CVE-2026-42257 + related)

Tool Before After
Trivy reported clear
Snyk reported clear

Made with Cursor

Clears Critical CVE-2026-42257 (and CVE-2026-42245/42258/47240/47242/47241)
by pinning above the fixed 0.5.15 line. Continues overriding JRuby's default gem.

Part of elastic/search-team#15476

Co-authored-by: Cursor <cursoragent@cursor.com>
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic enabled auto-merge (squash) August 4, 2026 07:47
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic merged commit 0cfafb2 into main Aug 4, 2026
2 checks passed
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic deleted the jan-kazlouski/15476-cve-2026-42257-fix branch August 4, 2026 07:54
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

💚 Backport PR(s) successfully created

Status Branch Result
1.0 #467

This backport PR will be merged automatically after passing CI.

Jan-Kazlouski-elastic added a commit that referenced this pull request Aug 4, 2026
Backports the following commits to 1.0:
 - [CVE-2026-42257] Bump net-imap to 0.5.15 (#461)

Co-authored-by: Jan-Kazlouski-elastic <jan.kazlouski@elastic.co>
Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants