IsItPatchedInstant security status for any software version
← All products

CVE-2015-9096

MEDIUM severity · CVSS 6.1 · CWE-93
6.1CVSS MEDIUM

Summary

Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges requiredNone
User interactionRequired
Confidentiality impactLow
Integrity impactLow
Availability impactNone
Exploit probability (EPSS)2%

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: https://github.com/ruby/ruby/commit/0827a7e52ba3d957a634b063bf5a391239b9ffee ↗

Last checked: Wed, 10 Jun 2026 22:18:30 UTC