{"id":"CVE-2026-55099","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-55099","summary":"icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares…","details":"icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membership test invokes the same method on child components, causing O(2^n) work relative to nesting depth. Component.from_ical accepts arbitrarily nested BEGIN:VEVENT blocks without a depth limit, so an attacker can submit a sub-kilobyte .ics file containing equal nested subtrees and trigger the cost when an application performs equality, inequality, membership, deduplication, test-assertion, round-trip, or normalization comparisons. Parsing alone does not trigger the issue, and comparisons that differ early short-circuit, but a few hundred bytes can pin a CPU core for minutes or indefinitely, causing denial of service in calendar sync or import endpoints, invite processing, and other comparison paths. This issue is fixed in version 7.1.3.","published":"2026-08-25T20:16:56.940","modified":"2026-08-25T20:16:56.940","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/collective/icalendar/commit/b6b2608ae3af6de40695b4e40f71847485aa0b49","label":"collective/icalendar@b6b2608"},"references":[{"type":"WEB","url":"https://github.com/collective/icalendar/commit/b6b2608ae3af6de40695b4e40f71847485aa0b49"},{"type":"WEB","url":"https://github.com/collective/icalendar/commit/cad40cd112c93fd142ec12cc5b37445a849b8a79"},{"type":"WEB","url":"https://github.com/collective/icalendar/releases/tag/v7.1.3"},{"type":"WEB","url":"https://github.com/collective/icalendar/security/advisories/GHSA-cv84-9p8j-fj68"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-25T20:16:56.940"}}