{"id":"CVE-2026-61915","title":"An issue was discovered in Cyrus IMAP before 3.12.4","summary":"An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION=\"BYPARAM@...\" against a resource with two o…","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-415"],"vendor":"cyrus","product":"imap","affected":["imap < 3.8.8","imap >= 3.9.0, < 3.10.4","imap >= 3.11.0, < 3.12.4"],"patched":["imap 3.12.4"],"published":"2026-09-09","updated":"2026-09-16","sourceUpdated":"2026-09-16T15:23:51.873","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-61915","references":[{"url":"https://cyrusimap.org","label":"cve@mitre.org"},{"url":"https://www.cyrusimap.org/3.12/imap/download/release-notes/3.10/x/3.10.4.html","label":"cve@mitre.org"},{"url":"https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.4.html","label":"cve@mitre.org"},{"url":"https://www.cyrusimap.org/3.12/imap/download/release-notes/3.8/x/3.8.8.html","label":"cve@mitre.org"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-61915.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-61915"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2526315"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-61915"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61915"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00258,"epssPercentile":0.17803,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T14:46:56.534339Z"},"ingestedAt":"2026-09-14T08:50:50.747Z","slug":"CVE-2026-61915","body":"## Overview\n\nAn issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION=\"BYPARAM@...\" against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.\n\n## Affected\n\n- `imap < 3.8.8`\n- `imap >= 3.9.0, < 3.10.4`\n- `imap >= 3.11.0, < 3.12.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `imap 3.12.4`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-61915.json)","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}