CVE-2026-61915: Double Free

Published Sep 9, 2026
·
Updated

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.

Affected Software

1 affected component
Cyrus Cyrus IMAP<3.12.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Cyrus IMAP to a version that resolves this vulnerability.

    Fixed in 3.12.4Patch VPATCH BYPARAM double-free

Event History

Sep 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated calendar user can trigger the flaw. The vulnerable request targets a CalDAV resource that has two or more properties of the kind matched by the selector.

2

What request is required to trigger the crash?

The attacker must send a VPATCH request using PATCH-ACTION="BYPARAM@...". Exploitation requires iterating over at least two matching properties, causing the selector memory to be freed more than once.

3

What is the operational impact?

A successful attack can crash a Cyrus CalDAV worker. The provided information identifies integrity and availability impacts, but does not describe confidentiality impact or code execution.

4

Which versions are affected?

Cyrus IMAP versions before 3.12.4 are affected according to the description. The provided release-note references also include 3.10.4, but the description does not explicitly state the full affected version ranges or whether that release contains a fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203