CVE-2026-61915
Undergoing Analysis Undergoing Analysis - In Progress

VPATCH BYPARAM Double-Free in Cyrus IMAP

Vulnerability report for CVE-2026-61915, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: MITRE

Description

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cyrus imap to 3.12.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-415 The product calls free() twice on the same memory address.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a double-free issue in Cyrus IMAP before version 3.12.4. It occurs when an authenticated calendar user sends a PATCH request with a specific parameter to a resource with multiple properties of the same kind. The memory handling flaw causes the program to free the same memory twice during processing, leading to a crash of the Cyrus CalDAV worker.

Detection Guidance

This vulnerability affects Cyrus IMAP versions before 3.12.4. To detect it, check your Cyrus IMAP server version using commands like 'cyrus-imapd --version' or 'rpm -qa | grep cyrus-imapd' on Linux systems. If the version is below 3.12.4, the system is vulnerable. No specific commands are provided in the context to actively detect exploitation attempts.

Impact Analysis

If exploited, this vulnerability could cause a denial of service by crashing the CalDAV worker, disrupting calendar services for users. An attacker with authenticated access could trigger this issue, potentially affecting availability of calendar data and related services.

Compliance Impact

The vulnerability involves a double-free issue in Cyrus IMAP that could crash a CalDAV worker, potentially leading to denial of service. This may impact compliance by disrupting availability of services handling personal or health data, but specific effects on GDPR or HIPAA depend on system configuration and data processing context.

Mitigation Strategies

Upgrade Cyrus IMAP to version 3.12.4 or later to address the VPATCH BYPARAM double-free vulnerability in the CalDAV component.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-61915. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart