PT-2026-97003 · Pypi · Calendar

CVE-2026-77399

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions icalendar versions 6.1.0 through 7.2.1
Description The vInt.from ical function accepts an attacker-controlled VALARM REPEAT value. Applications requesting alarm times may eagerly expand this value without an application-level limit. This unbounded expansion is reachable via Alarms.times and Alarms.active in versions starting with 6.1.0, and via Alarm.triggers in versions starting with 7.0.0. While parsing alone does not trigger the issue, accessing these properties can lead to excessive CPU and heap memory consumption, potentially stalling or terminating the service.
Recommendations Update to version 7.2.2.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77399
GHSA-QJCQ-Q7H7-R74V

Affected Products

Calendar