Skip to content

[1.0] [CVE-2026-42257] Bump net-imap to 0.5.15 (#461) - #467

Merged
Jan-Kazlouski-elastic merged 1 commit into
1.0from
backport/1.0/pr-461
Aug 4, 2026
Merged

[1.0] [CVE-2026-42257] Bump net-imap to 0.5.15 (#461)#467
Jan-Kazlouski-elastic merged 1 commit into
1.0from
backport/1.0/pr-461

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

Backports the following commits to 1.0:

### Part of elastic/search-team#15476

Also covers:
- elastic/search-team#15475 (CVE-2026-42245)
- elastic/search-team#15474 (CVE-2026-42258)
- elastic/search-team#14852 (CVE-2026-47240)
- elastic/search-team#14853 (CVE-2026-47242)
- elastic/search-team#14854 (CVE-2026-47241)

Resolves **CVE-2026-42257** (critical) — IMAP command injection via CRLF
in unvalidated input. Fixed in net-imap **0.5.15** (also clears
CVE-2026-42245 / 42258 / 47240 / 47242 / 47241).

#### Changes
- **`Gemfile` / `Gemfile.lock`**: pin `net-imap` `0.3.10` → `0.5.15`
- **`Dockerfile` / `Dockerfile.wolfi`**: comment update for the new pin
- **`NOTICE.txt`**: regenerated

#### Testing
- Full `make test`: 690 examples, 0 failures
- Scanner A/B (all 6 CVEs):

### Scanner A/B (`CVE-2026-42257` + related)

| Tool | Before | After |
|------|--------|-------|
| Trivy | reported | clear |
| Snyk | reported | clear |


Made with [Cursor](https://cursor.com)

Co-authored-by: Cursor <cursoragent@cursor.com>
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic merged commit f6958f4 into 1.0 Aug 4, 2026
2 checks passed
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic deleted the backport/1.0/pr-461 branch August 4, 2026 14:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant