{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-06T17:39:51.912","vulnerabilities":[{"cve":{"id":"CVE-2025-43857","sourceIdentifier":"security-advisories@github.com","published":"2025-04-28T16:15:33.440","lastModified":"2025-11-21T19:23:26.747","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there is a possibility for denial of service by memory exhaustion when net-imap reads server responses. At any time while the client is connected, a malicious server can send can send a \"literal\" byte count, which is automatically read by the client's receiver thread. The response reader immediately allocates memory for the number of bytes indicated by the server response. This should not be an issue when securely connecting to trusted IMAP servers that are well-behaved. It can affect insecure connections and buggy, untrusted, or compromised servers (for example, connecting to a user supplied hostname). This issue has been patched in versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5."},{"lang":"es","value":"Net::IMAP implementa la funcionalidad de cliente del Protocolo de Acceso a Mensajes de Internet (IMAP) en Ruby. En versiones anteriores a la 0.5.7, 0.4.20, 0.3.9 y 0.2.5, existía la posibilidad de denegación de servicio por agotamiento de memoria al leer las respuestas del servidor. Mientras el cliente esté conectado, un servidor malicioso puede enviar un recuento literal de bytes, que el hilo receptor del cliente lee automáticamente. El lector de la respuesta asigna inmediatamente memoria para la cantidad de bytes indicada por la respuesta del servidor. Esto no debería ser un problema al conectarse de forma segura a servidores IMAP confiables y con buen comportamiento. Puede afectar a conexiones inseguras y servidores con errores, no confiables o comprometidos (por ejemplo, al conectarse a un nombre de host proporcionado por el usuario). Este problema se ha corregido en las versiones 0.5.7, 0.4.20, 0.3.9 y 0.2.5."}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"},{"lang":"en","value":"CWE-405"},{"lang":"en","value":"CWE-770"},{"lang":"en","value":"CWE-789"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:net\\:\\:imap:*:*:*:*:*:ruby:*:*","versionEndExcluding":"0.2.5","matchCriteriaId":"A3CA044E-A527-4D63-8811-2A879D57595E"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:net\\:\\:imap:*:*:*:*:*:ruby:*:*","versionStartIncluding":"0.3.0","versionEndExcluding":"0.3.9","matchCriteriaId":"D4564036-BD61-4839-B08A-770C905618C4"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:net\\:\\:imap:*:*:*:*:*:ruby:*:*","versionStartIncluding":"0.4.0","versionEndExcluding":"0.4.20","matchCriteriaId":"7392FFDA-CCC8-4CB2-8731-5B5A3F15A0E3"},{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:net\\:\\:imap:*:*:*:*:*:ruby:*:*","versionStartIncluding":"0.5.0","versionEndExcluding":"0.5.7","matchCriteriaId":"BC238214-55BF-4EBA-A893-EDBB5E34A728"}]}]}],"references":[{"url":"https://github.com/ruby/net-imap/pull/442","source":"security-advisories@github.com","tags":["Issue Tracking","Patch"]},{"url":"https://github.com/ruby/net-imap/pull/444/commits/0ae8576c1a90bcd9573f81bdad4b4b824642d105#diff-53721cb4d9c3fb86b95cc8476ca2df90968ad8c481645220c607034399151462","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/ruby/net-imap/pull/445","source":"security-advisories@github.com","tags":["Issue Tracking","Patch"]},{"url":"https://github.com/ruby/net-imap/pull/446","source":"security-advisories@github.com","tags":["Issue Tracking","Patch"]},{"url":"https://github.com/ruby/net-imap/pull/447","source":"security-advisories@github.com","tags":["Issue Tracking","Patch"]},{"url":"https://github.com/ruby/net-imap/security/advisories/GHSA-j3g3-5qv5-52mj","source":"security-advisories@github.com","tags":["Vendor Advisory"]}]}}]}