OESA-2026-4106

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-4106
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-4106.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-4106
Upstream
Published
2026-09-25T01:28:27Z
Modified
2026-09-25T01:45:13Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
rubygem-mail security update
Details

A really Ruby Mail handler.

Security Fix(es):

Affected versions of this package are vulnerable to Improper Validation of Syntactic Correctness of Input through q_value_decode and b_value_decode in lib/mail/utilities.rb. An attacker can make a display name or local part decode to a different address than intended by supplying a malformed RFC 2047 encoded-word, including one that embeds extra encoded-word markers or additional text. The decoders only matched the first encoded-word and used a greedy charset capture, so a crafted header could cause the parsed From, To, or Reply-To value to omit or reshuffle literal text. Applications that display, compare, or authorize based on the decoded address can then present or act on a spoofed sender or recipient address.(CVE-2026-63435)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:24.03-LTS-SP4 / rubygem-mail

Package

Name
rubygem-mail
Purl
pkg:rpm/openEuler/rubygem-mail&distro=openEuler-24.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.8.1-2.oe2403sp4

Ecosystem specific

{
    "noarch": [
        "rubygem-mail-2.8.1-2.oe2403sp4.noarch.rpm",
        "rubygem-mail-doc-2.8.1-2.oe2403sp4.noarch.rpm"
    ],
    "src": [
        "rubygem-mail-2.8.1-2.oe2403sp4.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-4106.json"