CVE-2026-61915
MEDIUM
NVD
CVSS Score
4.2
Severity
MEDIUM
Published
Sep 09, 2026
Vendor
unknown
Description
An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.