CVE-2026-61915
An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.
- Published Sep 9, 2026
- CVSS 7.1 high
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available