Medium severity4.2NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026
CVE-2026-61915
CVE-2026-61915
Description
An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.12.4
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.