Hi,
The following vulnerability was published for python-icalendar.
CVE-2026-77399[0]:
| icalendar is an RFC 5545 compatible parser and generator of
| iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical
| accepts an attacker-controlled VALARM REPEAT value and applications
| that request alarm times can eagerly expand it without an
| application-level limit. Alarms.times and Alarms.active reach the
| unbounded expansion in versions starting with 6.1.0, while
| Alarm.triggers adds a second affected path starting with 7.0.0.
| Parsing alone does not trigger the issue, but accessing these
| properties can consume excessive CPU time and heap memory and
| terminate or stall a service. This issue is fixed in version 7.2.2.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-77399
https://www.cve.org/CVERecord?id=CVE-2026-77399
[1] https://github.com/collective/icalendar/security/advisories/GHSA-qjcq-q7h7-r74v
[2] https://github.com/collective/icalendar/commit/157f85137c65565a308bbcf4fdcc7d8ebce01267
Regards,
Salvatore