PT-2026-97003 · Pypi · Calendar
CVE-2026-77399
·
Published
2026-09-22
·
Updated
2026-09-23
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
icalendar versions 6.1.0 through 7.2.1
Description
The
vInt.from ical function accepts an attacker-controlled VALARM REPEAT value. Applications requesting alarm times may eagerly expand this value without an application-level limit. This unbounded expansion is reachable via Alarms.times and Alarms.active in versions starting with 6.1.0, and via Alarm.triggers in versions starting with 7.0.0. While parsing alone does not trigger the issue, accessing these properties can lead to excessive CPU and heap memory consumption, potentially stalling or terminating the service.Recommendations
Update to version 7.2.2.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Calendar