← לוח פגיעויות

CVE-2026-61915

גבוהה 7.1

תיאור (מקור, אנגלית)

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.

מדדים

CVSS 3.1
7.1 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-5/10/2026
CWE
CWE-415

מוצרים מושפעים

cyrus: imap

קישורים