Executive brief
Cyrus IMAP is an email, calendar, and contact server widely used in enterprise and university environments. An authenticated calendar user can crash the CalDAV service by sending a specially crafted PATCH request, causing a denial of service that may interrupt calendar access for multiple users.
Technical details
A double-free vulnerability exists in the CalDAV VPATCH request handler when processing PATCH-ACTION="BYPARAM@..." directives against resources with two or more matching properties. The memory selector is freed multiple times—once per iteration over matching properties—leading to a heap corruption and crash of the CalDAV worker process. The vulnerability requires an authenticated calendar user on the system and network access to the CalDAV service. An attacker can trigger the crash repeatedly to achieve denial of service. The issue is fixed in Cyrus IMAP 3.12.4 and later.
Affected products
- Cyrus Cyrus IMAP before 3.12.4
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Fixed in Cyrus IMAP 3.12.4