Ruby mail Gem Vulnerability: Email Address Spoofing Risk
- Severity
- HIGH
- Affected component
- mail (gem)
- Affected versions
- < 2.4.4 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.5, <= 1.2.5 or >= 1.2.6, <= 1.2.6 or >= 1.2.8, <= 1.2.8 or >= 1.2.9, <= 1.2.9 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.3.2, <= 1.3.2 or >= 1.3.3, <= 1.3.3 or >= 1.3.4, <= 1.3.4 or >= 1.3.5, <= 1.3.5 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, <= 1.6.0 or >= 2.0.3, <= 2.0.3 or >= 2.0.5, <= 2.0.5 or >= 2.1.0, <= 2.1.0 or >= 2.1.1, <= 2.1.1 or >= 2.1.2, <= 2.1.2 or >= 2.1.3, <= 2.1.3 or >= 2.1.5, <= 2.1.5 or >= 2.1.5.1, <= 2.1.5.1 or >= 2.1.5.2, <= 2.1.5.2 or >= 2.1.5.3, <= 2.1.5.3 or >= 2.2.0, <= 2.2.0 or >= 2.2.1, <= 2.2.1 or >= 2.2.10, <= 2.2.10 or >= 2.2.11, <= 2.2.11 or >= 2.2.12, <= 2.2.12 or >= 2.2.13, <= 2.2.13 or >= 2.2.14, <= 2.2.14 or >= 2.2.15, <= 2.2.15 or >= 2.2.16, <= 2.2.16 or >= 2.2.17, <= 2.2.17 or >= 2.2.18, <= 2.2.18 or >= 2.2.19, <= 2.2.19 or >= 2.2.2, <= 2.2.2 or >= 2.2.20, <= 2.2.20 or >= 2.2.3, <= 2.2.3 or >= 2.2.4, <= 2.2.4 or >= 2.2.5, <= 2.2.5 or >= 2.2.5.1, <= 2.2.5.1 or >= 2.2.5.2, <= 2.2.5.2 or >= 2.2.6, <= 2.2.6 or >= 2.2.6.1, <= 2.2.6.1 or >= 2.2.7, <= 2.2.7 or >= 2.2.9, <= 2.2.9 or >= 2.2.9.1, <= 2.2.9.1 or >= 2.3.0, <= 2.3.0 or >= 2.3.2, <= 2.3.2 or >= 2.3.3, <= 2.3.3 or >= 2.4.0, <= 2.4.0 or >= 2.4.1, <= 2.4.1 or >= 2.4.3, <= 2.4.3 or < 2.2.15 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.5, <= 1.2.5 or >= 1.2.6, <= 1.2.6 or >= 1.2.8, <= 1.2.8 or >= 1.2.9, <= 1.2.9 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.3.2, <= 1.3.2 or >= 1.3.3, <= 1.3.3 or >= 1.3.4, <= 1.3.4 or >= 1.3.5, <= 1.3.5 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, <= 1.6.0 or >= 2.0.3, <= 2.0.3 or >= 2.0.5, <= 2.0.5 or >= 2.1.0, <= 2.1.0 or >= 2.1.1, <= 2.1.1 or >= 2.1.2, <= 2.1.2 or >= 2.1.3, <= 2.1.3 or >= 2.1.5, <= 2.1.5 or >= 2.1.5.1, <= 2.1.5.1 or >= 2.1.5.2, <= 2.1.5.2 or >= 2.1.5.3, <= 2.1.5.3 or >= 2.2.0, <= 2.2.0 or >= 2.2.1, <= 2.2.1 or >= 2.2.10, <= 2.2.10 or >= 2.2.11, <= 2.2.11 or >= 2.2.12, <= 2.2.12 or >= 2.2.13, <= 2.2.13 or >= 2.2.14, <= 2.2.14 or >= 2.2.2, <= 2.2.2 or >= 2.2.3, <= 2.2.3 or >= 2.2.4, <= 2.2.4 or >= 2.2.5, <= 2.2.5 or >= 2.2.5.1, <= 2.2.5.1 or >= 2.2.5.2, <= 2.2.5.2 or >= 2.2.6, <= 2.2.6 or >= 2.2.6.1, <= 2.2.6.1 or >= 2.2.7, <= 2.2.7 or >= 2.2.9, <= 2.2.9 or >= 2.2.9.1, <= 2.2.9.1 or < 2.9.1 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.5, <= 1.2.5 or >= 1.2.6, <= 1.2.6 or >= 1.2.8, <= 1.2.8 or >= 1.2.9, <= 1.2.9 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.3.2, <= 1.3.2 or >= 1.3.3, <= 1.3.3 or >= 1.3.4, <= 1.3.4 or >= 1.3.5, <= 1.3.5 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, <= 1.6.0 or >= 2.0.3, <= 2.0.3 or >= 2.0.5, <= 2.0.5 or >= 2.1.0, <= 2.1.0 or >= 2.1.1, <= 2.1.1 or >= 2.1.2, <= 2.1.2 or >= 2.1.3, <= 2.1.3 or >= 2.1.5, <= 2.1.5 or >= 2.1.5.1, <= 2.1.5.1 or >= 2.1.5.2, <= 2.1.5.2 or >= 2.1.5.3, <= 2.1.5.3 or >= 2.2.0, <= 2.2.0 or >= 2.2.1, <= 2.2.1 or >= 2.2.10, <= 2.2.10 or >= 2.2.11, <= 2.2.11 or >= 2.2.12, <= 2.2.12 or >= 2.2.13, <= 2.2.13 or >= 2.2.14, <= 2.2.14 or >= 2.2.15, <= 2.2.15 or >= 2.2.16, <= 2.2.16 or >= 2.2.17, <= 2.2.17 or >= 2.2.18, <= 2.2.18 or >= 2.2.19, <= 2.2.19 or >= 2.2.2, <= 2.2.2 or >= 2.2.20, <= 2.2.20 or >= 2.2.3, <= 2.2.3 or >= 2.2.4, <= 2.2.4 or >= 2.2.5, <= 2.2.5 or >= 2.2.5.1, <= 2.2.5.1 or >= 2.2.5.2, <= 2.2.5.2 or >= 2.2.6, <= 2.2.6 or >= 2.2.6.1, <= 2.2.6.1 or >= 2.2.7, <= 2.2.7 or >= 2.2.9, <= 2.2.9 or >= 2.2.9.1, <= 2.2.9.1 or >= 2.3.0, <= 2.3.0 or >= 2.3.2, <= 2.3.2 or >= 2.3.3, <= 2.3.3 or >= 2.4.0, <= 2.4.0 or >= 2.4.1, <= 2.4.1 or >= 2.4.3, <= 2.4.3 or >= 2.4.4, <= 2.4.4 or >= 2.5.2, <= 2.5.2 or >= 2.5.3, <= 2.5.3 or >= 2.5.4, <= 2.5.4 or >= 2.5.5, <= 2.5.5 or >= 2.5.5.rc1, <= 2.5.5.rc1 or >= 2.6.0, <= 2.6.0 or >= 2.6.1, <= 2.6.1 or >= 2.6.3, <= 2.6.3 or >= 2.6.4, <= 2.6.4 or >= 2.6.4.rc1, <= 2.6.4.rc1 or >= 2.6.4.rc2, <= 2.6.4.rc2 or >= 2.6.5, <= 2.6.5 or >= 2.6.5.rc1, <= 2.6.5.rc1 or >= 2.6.6, <= 2.6.6 or >= 2.6.6.rc1, <= 2.6.6.rc1 or >= 2.7.0, <= 2.7.0 or >= 2.7.0.rc1, <= 2.7.0.rc1 or >= 2.7.0.rc2, <= 2.7.0.rc2 or >= 2.7.0.rc3, <= 2.7.0.rc3 or >= 2.7.1, <= 2.7.1 or >= 2.7.1.rc1, <= 2.7.1.rc1 or >= 2.8.0, <= 2.8.0 or >= 2.8.0.1, <= 2.8.0.1 or >= 2.8.0.1.rc1, <= 2.8.0.1.rc1 or >= 2.8.0.rc1, <= 2.8.0.rc1 or >= 2.8.0.rc2, <= 2.8.0.rc2 or >= 2.8.0.rc3, <= 2.8.0.rc3 or >= 2.8.1, <= 2.8.1 or >= 2.8.1.rc2, <= 2.8.1.rc2 or >= 2.9.0, <= 2.9.0 or >= 2.9.0.beta1, <= 2.9.0.beta1 or >= 2.9.0.beta2, <= 2.9.0.beta2 or < 2.5.5 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.5, <= 1.2.5 or >= 1.2.6, <= 1.2.6 or >= 1.2.8, <= 1.2.8 or >= 1.2.9, <= 1.2.9 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.3.2, <= 1.3.2 or >= 1.3.3, <= 1.3.3 or >= 1.3.4, <= 1.3.4 or >= 1.3.5, <= 1.3.5 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, <= 1.6.0 or >= 2.0.3, <= 2.0.3 or >= 2.0.5, <= 2.0.5 or >= 2.1.0, <= 2.1.0 or >= 2.1.1, <= 2.1.1 or >= 2.1.2, <= 2.1.2 or >= 2.1.3, <= 2.1.3 or >= 2.1.5, <= 2.1.5 or >= 2.1.5.1, <= 2.1.5.1 or >= 2.1.5.2, <= 2.1.5.2 or >= 2.1.5.3, <= 2.1.5.3 or >= 2.2.0, <= 2.2.0 or >= 2.2.1, <= 2.2.1 or >= 2.2.10, <= 2.2.10 or >= 2.2.11, <= 2.2.11 or >= 2.2.12, <= 2.2.12 or >= 2.2.13, <= 2.2.13 or >= 2.2.14, <= 2.2.14 or >= 2.2.15, <= 2.2.15 or >= 2.2.16, <= 2.2.16 or >= 2.2.17, <= 2.2.17 or >= 2.2.18, <= 2.2.18 or >= 2.2.19, <= 2.2.19 or >= 2.2.2, <= 2.2.2 or >= 2.2.20, <= 2.2.20 or >= 2.2.3, <= 2.2.3 or >= 2.2.4, <= 2.2.4 or >= 2.2.5, <= 2.2.5 or >= 2.2.5.1, <= 2.2.5.1 or >= 2.2.5.2, <= 2.2.5.2 or >= 2.2.6, <= 2.2.6 or >= 2.2.6.1, <= 2.2.6.1 or >= 2.2.7, <= 2.2.7 or >= 2.2.9, <= 2.2.9 or >= 2.2.9.1, <= 2.2.9.1 or >= 2.3.0, <= 2.3.0 or >= 2.3.2, <= 2.3.2 or >= 2.3.3, <= 2.3.3 or >= 2.4.0, <= 2.4.0 or >= 2.4.1, <= 2.4.1 or >= 2.4.3, <= 2.4.3 or >= 2.4.4, <= 2.4.4 or >= 2.5.2, <= 2.5.2 or >= 2.5.3, <= 2.5.3 or >= 2.5.4, <= 2.5.4 or >= 2.5.5.rc1, <= 2.5.5.rc1 or < 2.4.3 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.5, <= 1.2.5 or >= 1.2.6, <= 1.2.6 or >= 1.2.8, <= 1.2.8 or >= 1.2.9, <= 1.2.9 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.3.2, <= 1.3.2 or >= 1.3.3, <= 1.3.3 or >= 1.3.4, <= 1.3.4 or >= 1.3.5, <= 1.3.5 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, <= 1.6.0 or >= 2.0.3, <= 2.0.3 or >= 2.0.5, <= 2.0.5 or >= 2.1.0, <= 2.1.0 or >= 2.1.1, <= 2.1.1 or >= 2.1.2, <= 2.1.2 or >= 2.1.3, <= 2.1.3 or >= 2.1.5, <= 2.1.5 or >= 2.1.5.1, <= 2.1.5.1 or >= 2.1.5.2, <= 2.1.5.2 or >= 2.1.5.3, <= 2.1.5.3 or >= 2.2.0, <= 2.2.0 or >= 2.2.1, <= 2.2.1 or >= 2.2.10, <= 2.2.10 or >= 2.2.11, <= 2.2.11 or >= 2.2.12, <= 2.2.12 or >= 2.2.13, <= 2.2.13 or >= 2.2.14, <= 2.2.14 or >= 2.2.15, <= 2.2.15 or >= 2.2.16, <= 2.2.16 or >= 2.2.17, <= 2.2.17 or >= 2.2.18, <= 2.2.18 or >= 2.2.19, <= 2.2.19 or >= 2.2.2, <= 2.2.2 or >= 2.2.20, <= 2.2.20 or >= 2.2.3, <= 2.2.3 or >= 2.2.4, <= 2.2.4 or >= 2.2.5, <= 2.2.5 or >= 2.2.5.1, <= 2.2.5.1 or >= 2.2.5.2, <= 2.2.5.2 or >= 2.2.6, <= 2.2.6 or >= 2.2.6.1, <= 2.2.6.1 or >= 2.2.7, <= 2.2.7 or >= 2.2.9, <= 2.2.9 or >= 2.2.9.1, <= 2.2.9.1 or >= 2.3.0, <= 2.3.0 or >= 2.3.2, <= 2.3.2 or >= 2.3.3, <= 2.3.3 or >= 2.4.0, <= 2.4.0 or >= 2.4.1, <= 2.4.1
- Patched version
- Not yet available
A confirmed vulnerability in the Ruby mail gem allows email address spoofing due to improper decoding of RFC 2047 encoded-words. This affects email display and authorization based on decoded header values.
What happened
The vulnerability in the mail gem for Ruby arises from its decoders for RFC 2047 encoded-words. These decoders only process the first encoded-word in a string and use a greedy pattern, which can be exploited to spoof email addresses. This issue impacts the display and authorization mechanisms that rely on decoded header values.
The vulnerability was first flagged on September 2, 2026, and confirmed on September 3, 2026. It has not been exploited in the wild as of the latest reports. The affected versions of the mail gem are extensive, covering a wide range of releases from version 1.0.0 to 2.9.1, with specific versions excluded as noted in the affected components list.
What to do about it
- Upgrade to a version of the mail gem that includes a fix for this issue, if available.
- Review and sanitize email header values in your application to mitigate the risk of spoofing.
- Monitor the primary sources for updates on patched versions and further details.
- Consult the primary sources for the most current information on affected versions and fixes.
How 0Day would have caught this
mail is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using a version of the mail gem less than 2.4.4 or any version between 1.0.0 and 2.9.1, excluding specific versions as listed in the affected components.
What should I do right now?
Upgrade to a secure version of the mail gem and review your application's handling of email headers to prevent spoofing.
Is there an official fix available?
An official fix may be available. Check the primary sources for the latest information on patched versions.
Sources
- NCSC-2026-0338 [1.00] [M/H] Kwetsbaarheden verholpen in Cisco Nexus 9000 Series, IOS XR Software en Secure Email
- NCSC-2026-0349 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Exchange server
- [GHSA-mvxr-6m87-mv2q] Mail: Email address spoofing via malformed RFC 2047 encoded-words
- [GHSA-2x7j-588g-ccc2] Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
- [CVE-2026-10196] CVSS 9.8 CRITICAL
- [CVE-2026-15354] CVSS 9.8 CRITICAL
- [CVE-2026-75816] CVSS 9.8 CRITICAL
- [CVE-2026-85424] CVSS 9.8 CRITICAL