GEM · SEPTEMBER 2026 · CONFIRMED

Ruby mail Gem Vulnerability: Email Address Spoofing Risk

Severity
HIGH
Affected component
mail (gem)
Affected versions
< 2.4.4 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.5, <= 1.2.5 or >= 1.2.6, <= 1.2.6 or >= 1.2.8, <= 1.2.8 or >= 1.2.9, <= 1.2.9 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.3.2, <= 1.3.2 or >= 1.3.3, <= 1.3.3 or >= 1.3.4, <= 1.3.4 or >= 1.3.5, <= 1.3.5 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, <= 1.6.0 or >= 2.0.3, <= 2.0.3 or >= 2.0.5, <= 2.0.5 or >= 2.1.0, <= 2.1.0 or >= 2.1.1, <= 2.1.1 or >= 2.1.2, <= 2.1.2 or >= 2.1.3, <= 2.1.3 or >= 2.1.5, <= 2.1.5 or >= 2.1.5.1, <= 2.1.5.1 or >= 2.1.5.2, <= 2.1.5.2 or >= 2.1.5.3, <= 2.1.5.3 or >= 2.2.0, <= 2.2.0 or >= 2.2.1, <= 2.2.1 or >= 2.2.10, <= 2.2.10 or >= 2.2.11, <= 2.2.11 or >= 2.2.12, <= 2.2.12 or >= 2.2.13, <= 2.2.13 or >= 2.2.14, <= 2.2.14 or >= 2.2.15, <= 2.2.15 or >= 2.2.16, <= 2.2.16 or >= 2.2.17, <= 2.2.17 or >= 2.2.18, <= 2.2.18 or >= 2.2.19, <= 2.2.19 or >= 2.2.2, <= 2.2.2 or >= 2.2.20, <= 2.2.20 or >= 2.2.3, <= 2.2.3 or >= 2.2.4, <= 2.2.4 or >= 2.2.5, <= 2.2.5 or >= 2.2.5.1, <= 2.2.5.1 or >= 2.2.5.2, <= 2.2.5.2 or >= 2.2.6, <= 2.2.6 or >= 2.2.6.1, <= 2.2.6.1 or >= 2.2.7, <= 2.2.7 or >= 2.2.9, <= 2.2.9 or >= 2.2.9.1, <= 2.2.9.1 or >= 2.3.0, <= 2.3.0 or >= 2.3.2, <= 2.3.2 or >= 2.3.3, <= 2.3.3 or >= 2.4.0, <= 2.4.0 or >= 2.4.1, <= 2.4.1 or >= 2.4.3, <= 2.4.3 or < 2.2.15 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.5, <= 1.2.5 or >= 1.2.6, <= 1.2.6 or >= 1.2.8, <= 1.2.8 or >= 1.2.9, <= 1.2.9 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.3.2, <= 1.3.2 or >= 1.3.3, <= 1.3.3 or >= 1.3.4, <= 1.3.4 or >= 1.3.5, <= 1.3.5 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, <= 1.6.0 or >= 2.0.3, <= 2.0.3 or >= 2.0.5, <= 2.0.5 or >= 2.1.0, <= 2.1.0 or >= 2.1.1, <= 2.1.1 or >= 2.1.2, <= 2.1.2 or >= 2.1.3, <= 2.1.3 or >= 2.1.5, <= 2.1.5 or >= 2.1.5.1, <= 2.1.5.1 or >= 2.1.5.2, <= 2.1.5.2 or >= 2.1.5.3, <= 2.1.5.3 or >= 2.2.0, <= 2.2.0 or >= 2.2.1, <= 2.2.1 or >= 2.2.10, <= 2.2.10 or >= 2.2.11, <= 2.2.11 or >= 2.2.12, <= 2.2.12 or >= 2.2.13, <= 2.2.13 or >= 2.2.14, <= 2.2.14 or >= 2.2.2, <= 2.2.2 or >= 2.2.3, <= 2.2.3 or >= 2.2.4, <= 2.2.4 or >= 2.2.5, <= 2.2.5 or >= 2.2.5.1, <= 2.2.5.1 or >= 2.2.5.2, <= 2.2.5.2 or >= 2.2.6, <= 2.2.6 or >= 2.2.6.1, <= 2.2.6.1 or >= 2.2.7, <= 2.2.7 or >= 2.2.9, <= 2.2.9 or >= 2.2.9.1, <= 2.2.9.1 or < 2.9.1 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.5, <= 1.2.5 or >= 1.2.6, <= 1.2.6 or >= 1.2.8, <= 1.2.8 or >= 1.2.9, <= 1.2.9 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.3.2, <= 1.3.2 or >= 1.3.3, <= 1.3.3 or >= 1.3.4, <= 1.3.4 or >= 1.3.5, <= 1.3.5 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, <= 1.6.0 or >= 2.0.3, <= 2.0.3 or >= 2.0.5, <= 2.0.5 or >= 2.1.0, <= 2.1.0 or >= 2.1.1, <= 2.1.1 or >= 2.1.2, <= 2.1.2 or >= 2.1.3, <= 2.1.3 or >= 2.1.5, <= 2.1.5 or >= 2.1.5.1, <= 2.1.5.1 or >= 2.1.5.2, <= 2.1.5.2 or >= 2.1.5.3, <= 2.1.5.3 or >= 2.2.0, <= 2.2.0 or >= 2.2.1, <= 2.2.1 or >= 2.2.10, <= 2.2.10 or >= 2.2.11, <= 2.2.11 or >= 2.2.12, <= 2.2.12 or >= 2.2.13, <= 2.2.13 or >= 2.2.14, <= 2.2.14 or >= 2.2.15, <= 2.2.15 or >= 2.2.16, <= 2.2.16 or >= 2.2.17, <= 2.2.17 or >= 2.2.18, <= 2.2.18 or >= 2.2.19, <= 2.2.19 or >= 2.2.2, <= 2.2.2 or >= 2.2.20, <= 2.2.20 or >= 2.2.3, <= 2.2.3 or >= 2.2.4, <= 2.2.4 or >= 2.2.5, <= 2.2.5 or >= 2.2.5.1, <= 2.2.5.1 or >= 2.2.5.2, <= 2.2.5.2 or >= 2.2.6, <= 2.2.6 or >= 2.2.6.1, <= 2.2.6.1 or >= 2.2.7, <= 2.2.7 or >= 2.2.9, <= 2.2.9 or >= 2.2.9.1, <= 2.2.9.1 or >= 2.3.0, <= 2.3.0 or >= 2.3.2, <= 2.3.2 or >= 2.3.3, <= 2.3.3 or >= 2.4.0, <= 2.4.0 or >= 2.4.1, <= 2.4.1 or >= 2.4.3, <= 2.4.3 or >= 2.4.4, <= 2.4.4 or >= 2.5.2, <= 2.5.2 or >= 2.5.3, <= 2.5.3 or >= 2.5.4, <= 2.5.4 or >= 2.5.5, <= 2.5.5 or >= 2.5.5.rc1, <= 2.5.5.rc1 or >= 2.6.0, <= 2.6.0 or >= 2.6.1, <= 2.6.1 or >= 2.6.3, <= 2.6.3 or >= 2.6.4, <= 2.6.4 or >= 2.6.4.rc1, <= 2.6.4.rc1 or >= 2.6.4.rc2, <= 2.6.4.rc2 or >= 2.6.5, <= 2.6.5 or >= 2.6.5.rc1, <= 2.6.5.rc1 or >= 2.6.6, <= 2.6.6 or >= 2.6.6.rc1, <= 2.6.6.rc1 or >= 2.7.0, <= 2.7.0 or >= 2.7.0.rc1, <= 2.7.0.rc1 or >= 2.7.0.rc2, <= 2.7.0.rc2 or >= 2.7.0.rc3, <= 2.7.0.rc3 or >= 2.7.1, <= 2.7.1 or >= 2.7.1.rc1, <= 2.7.1.rc1 or >= 2.8.0, <= 2.8.0 or >= 2.8.0.1, <= 2.8.0.1 or >= 2.8.0.1.rc1, <= 2.8.0.1.rc1 or >= 2.8.0.rc1, <= 2.8.0.rc1 or >= 2.8.0.rc2, <= 2.8.0.rc2 or >= 2.8.0.rc3, <= 2.8.0.rc3 or >= 2.8.1, <= 2.8.1 or >= 2.8.1.rc2, <= 2.8.1.rc2 or >= 2.9.0, <= 2.9.0 or >= 2.9.0.beta1, <= 2.9.0.beta1 or >= 2.9.0.beta2, <= 2.9.0.beta2 or < 2.5.5 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.5, <= 1.2.5 or >= 1.2.6, <= 1.2.6 or >= 1.2.8, <= 1.2.8 or >= 1.2.9, <= 1.2.9 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.3.2, <= 1.3.2 or >= 1.3.3, <= 1.3.3 or >= 1.3.4, <= 1.3.4 or >= 1.3.5, <= 1.3.5 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, <= 1.6.0 or >= 2.0.3, <= 2.0.3 or >= 2.0.5, <= 2.0.5 or >= 2.1.0, <= 2.1.0 or >= 2.1.1, <= 2.1.1 or >= 2.1.2, <= 2.1.2 or >= 2.1.3, <= 2.1.3 or >= 2.1.5, <= 2.1.5 or >= 2.1.5.1, <= 2.1.5.1 or >= 2.1.5.2, <= 2.1.5.2 or >= 2.1.5.3, <= 2.1.5.3 or >= 2.2.0, <= 2.2.0 or >= 2.2.1, <= 2.2.1 or >= 2.2.10, <= 2.2.10 or >= 2.2.11, <= 2.2.11 or >= 2.2.12, <= 2.2.12 or >= 2.2.13, <= 2.2.13 or >= 2.2.14, <= 2.2.14 or >= 2.2.15, <= 2.2.15 or >= 2.2.16, <= 2.2.16 or >= 2.2.17, <= 2.2.17 or >= 2.2.18, <= 2.2.18 or >= 2.2.19, <= 2.2.19 or >= 2.2.2, <= 2.2.2 or >= 2.2.20, <= 2.2.20 or >= 2.2.3, <= 2.2.3 or >= 2.2.4, <= 2.2.4 or >= 2.2.5, <= 2.2.5 or >= 2.2.5.1, <= 2.2.5.1 or >= 2.2.5.2, <= 2.2.5.2 or >= 2.2.6, <= 2.2.6 or >= 2.2.6.1, <= 2.2.6.1 or >= 2.2.7, <= 2.2.7 or >= 2.2.9, <= 2.2.9 or >= 2.2.9.1, <= 2.2.9.1 or >= 2.3.0, <= 2.3.0 or >= 2.3.2, <= 2.3.2 or >= 2.3.3, <= 2.3.3 or >= 2.4.0, <= 2.4.0 or >= 2.4.1, <= 2.4.1 or >= 2.4.3, <= 2.4.3 or >= 2.4.4, <= 2.4.4 or >= 2.5.2, <= 2.5.2 or >= 2.5.3, <= 2.5.3 or >= 2.5.4, <= 2.5.4 or >= 2.5.5.rc1, <= 2.5.5.rc1 or < 2.4.3 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.5, <= 1.2.5 or >= 1.2.6, <= 1.2.6 or >= 1.2.8, <= 1.2.8 or >= 1.2.9, <= 1.2.9 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.3.2, <= 1.3.2 or >= 1.3.3, <= 1.3.3 or >= 1.3.4, <= 1.3.4 or >= 1.3.5, <= 1.3.5 or >= 1.4.0, <= 1.4.0 or >= 1.4.1, <= 1.4.1 or >= 1.4.2, <= 1.4.2 or >= 1.4.3, <= 1.4.3 or >= 1.5.0, <= 1.5.0 or >= 1.5.1, <= 1.5.1 or >= 1.5.2, <= 1.5.2 or >= 1.5.3, <= 1.5.3 or >= 1.5.4, <= 1.5.4 or >= 1.6.0, <= 1.6.0 or >= 2.0.3, <= 2.0.3 or >= 2.0.5, <= 2.0.5 or >= 2.1.0, <= 2.1.0 or >= 2.1.1, <= 2.1.1 or >= 2.1.2, <= 2.1.2 or >= 2.1.3, <= 2.1.3 or >= 2.1.5, <= 2.1.5 or >= 2.1.5.1, <= 2.1.5.1 or >= 2.1.5.2, <= 2.1.5.2 or >= 2.1.5.3, <= 2.1.5.3 or >= 2.2.0, <= 2.2.0 or >= 2.2.1, <= 2.2.1 or >= 2.2.10, <= 2.2.10 or >= 2.2.11, <= 2.2.11 or >= 2.2.12, <= 2.2.12 or >= 2.2.13, <= 2.2.13 or >= 2.2.14, <= 2.2.14 or >= 2.2.15, <= 2.2.15 or >= 2.2.16, <= 2.2.16 or >= 2.2.17, <= 2.2.17 or >= 2.2.18, <= 2.2.18 or >= 2.2.19, <= 2.2.19 or >= 2.2.2, <= 2.2.2 or >= 2.2.20, <= 2.2.20 or >= 2.2.3, <= 2.2.3 or >= 2.2.4, <= 2.2.4 or >= 2.2.5, <= 2.2.5 or >= 2.2.5.1, <= 2.2.5.1 or >= 2.2.5.2, <= 2.2.5.2 or >= 2.2.6, <= 2.2.6 or >= 2.2.6.1, <= 2.2.6.1 or >= 2.2.7, <= 2.2.7 or >= 2.2.9, <= 2.2.9 or >= 2.2.9.1, <= 2.2.9.1 or >= 2.3.0, <= 2.3.0 or >= 2.3.2, <= 2.3.2 or >= 2.3.3, <= 2.3.3 or >= 2.4.0, <= 2.4.0 or >= 2.4.1, <= 2.4.1
Patched version
Not yet available
GHSA-MVXR-6M87-MV2Q

A confirmed vulnerability in the Ruby mail gem allows email address spoofing due to improper decoding of RFC 2047 encoded-words. This affects email display and authorization based on decoded header values.

What happened

The vulnerability in the mail gem for Ruby arises from its decoders for RFC 2047 encoded-words. These decoders only process the first encoded-word in a string and use a greedy pattern, which can be exploited to spoof email addresses. This issue impacts the display and authorization mechanisms that rely on decoded header values.

The vulnerability was first flagged on September 2, 2026, and confirmed on September 3, 2026. It has not been exploited in the wild as of the latest reports. The affected versions of the mail gem are extensive, covering a wide range of releases from version 1.0.0 to 2.9.1, with specific versions excluded as noted in the affected components list.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If mail is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using a version of the mail gem less than 2.4.4 or any version between 1.0.0 and 2.9.1, excluding specific versions as listed in the affected components.

What should I do right now?

Upgrade to a secure version of the mail gem and review your application's handling of email headers to prevent spoofing.

Is there an official fix available?

An official fix may be available. Check the primary sources for the latest information on patched versions.

Sources

Join the 0Day waitlist →

← Back to all threats