Description
An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.
Published: 2026-09-09
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a double‑free in the CalDAV worker when a PATCH request containing PATCH‑ACTION="BYPARAM@…" is processed for a calendar resource that has two or more properties of the matched kind. The flaw is triggered only by an authenticated calendar user and results in the selector memory being freed twice, causing the CalDAV worker to crash. This leads to a denial of service; the description does not indicate any data disclosure or code execution.

Affected Systems

The affected vendor is Cyrus IMAP. Versions before 3.12.4 are impacted, including releases 3.8.8, 3.10.4 and earlier 3.12.x builds.

Risk and Exploitability

The CVSS score of 4.2 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user with calendar write access to send a crafted PATCH request. Because the flaw only causes a process crash, the impact is limited to the CalDAV worker and may require a service restart, but it presents a realistic threat in environments where such users exist.

Generated by OpenCVE AI on September 9, 2026 at 22:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Cyrus IMAP to version 3.12.4 or later, as indicated in the official release notes.
  • Restart the CalDAV worker process to clear any lingering instances after upgrading.
  • Monitor system logs for repeated CalDAV worker crashes to confirm the vulnerability has been mitigated.

Generated by OpenCVE AI on September 9, 2026 at 22:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Cyrus
Cyrus imap
CPEs cpe:2.3:a:cyrus:imap:*:*:*:*:*:*:*:*
Vendors & Products Cyrus
Cyrus imap

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Authenticated Calendar User Can Trigger Double‑Free Crash in Cyrus CalDAV Worker cyrus-imapd: cyrus-imapd: VPATCH BYPARAM double-free in CalDAV
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Authenticated Calendar User Can Trigger Double‑Free Crash in Cyrus CalDAV Worker

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.
First Time appeared Cyrusimap
Cyrusimap cyrus Imap
Weaknesses CWE-415
CPEs cpe:2.3:a:cyrusimap:cyrus_imap:*:*:*:*:*:*:*:*
Vendors & Products Cyrusimap
Cyrusimap cyrus Imap
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-10T14:47:05.215Z

Reserved: 2026-07-13T00:00:00.000Z

Link: CVE-2026-61915

cve-icon Vulnrichment

Updated: 2026-09-10T14:47:00.529Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T20:18:36.943

Modified: 2026-09-16T15:23:51.873

Link: CVE-2026-61915

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T07:44:04Z

Links: CVE-2026-61915 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:30:12Z

Weaknesses