Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-63435— Mail: Email address spoofing via malformed RFC 2047 encoded-words

Quick assessment

Affected
mikel mail
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

邮件(Mail) 是一个用于 Ruby 的互联网库,旨在处理电子邮件的生成、解析和发送。在 2.9.1 版本之前, 和 在处理 RFC 2047 编码字解码时,使用了单个 以及过于贪婪的字符集捕获逻辑,导致只能正确解码第一个 RFC 2047 编码字,并对前后相邻或后续文本的处理出现错误。 攻击者可以构造一个格式异常的编码字,嵌入在地址的显示名(display name)或本地部分中,使其跨越 分隔符,从而导致解码后的 、 或 头部的值与人类审查者或下游解析器所查看的原始值不一致。这种不一致可能引发发件人或收件人伪

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1565.001 · Stored Data Manipulation
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63435

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Mail: Email address spoofing via malformed RFC 2047 encoded-words
Source: CVE Program / CVE List V5
Vulnerability Description
Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_decode used a single String#match and an overly greedy charset capture to decode only the first RFC 2047 encoded-word and mishandle surrounding or subsequent text. A crafted malformed encoded-word in an address display name or local part could cross ? delimiters and make decoded From, To, or Reply-To header values differ from the raw values inspected by a human reviewer or downstream parser, enabling apparent sender or recipient spoofing, phishing, or authorization-check bypass. This issue is fixed in version 2.9.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
解释冲突
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
mikel mail < 2.9.1 -

II. Public POCs for CVE-2026-63435

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63435

登录查看更多情报信息。

Other References for CVE-2026-63435 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-63435

No comments yet


Leave a comment