---
cve: "CVE-2026-55099"
severity: "HIGH"
cvss: 7.5
epss: "0.4%"
vendor: "collective"
kev: false
exploited: false
published: "2026-08-25 20:16:56"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-28T03:10:15+02:00"
---

# CVE-2026-55099

> 7.5 HIGH · 🧪 PoC

## Beschreibung

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membership test invokes the same method on child components, causing O(2^n) work relative to nesting depth. Component.from_ical accepts arbitrarily nested BEGIN:VEVENT blocks without a depth limit, so an attacker can submit a sub-kilobyte .ics file containing equal nested subtrees and trigger the cost when an application performs equality, inequality, membership, deduplication, test-assertion, round-trip, or normalization comparisons. Parsing alone does not trigger the issue, and comparisons that differ early short-circuit, but a few hundred bytes can pin a CPU core for minutes or indefinitely, causing denial of service in calendar sync or import endpoints, invite processing, and other comparison paths. This issue is fixed in version 7.1.3.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **poc**
  - Automatable: **yes**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- b6b2608ae3af6de40695b4e40f71847485aa0b49 (Commit)
- cad40cd112c93fd142ec12cc5b37445a849b8a79 (Commit)

## Referenzen

- <https://github.com/collective/icalendar/security/advisories/GHSA-cv84-9p8j-fj68>
- <https://github.com/collective/icalendar/commit/b6b2608ae3af6de40695b4e40f71847485aa0b49>
- <https://github.com/collective/icalendar/commit/cad40cd112c93fd142ec12cc5b37445a849b8a79>
- <https://github.com/collective/icalendar/releases/tag/v7.1.3>
- <http://www.openwall.com/lists/oss-security/2026/06/23/8>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-55099) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
