#1148817 python-icalendar: CVE-2026-77399

Package:
src:python-icalendar
Source:
src:python-icalendar
Submitter:
Salvatore Bonaccorso
Date:
2026-09-24 05:13:02 UTC
Severity:
normal
Tags:
#1148817#5
Date:
2026-09-24 05:11:58 UTC
From:
To:
Hi,

The following vulnerability was published for python-icalendar.

CVE-2026-77399[0]:
| icalendar is an RFC 5545 compatible parser and generator of
| iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical
| accepts an attacker-controlled VALARM REPEAT value and applications
| that request alarm times can eagerly expand it without an
| application-level limit. Alarms.times and Alarms.active reach the
| unbounded expansion in versions starting with 6.1.0, while
| Alarm.triggers adds a second affected path starting with 7.0.0.
| Parsing alone does not trigger the issue, but accessing these
| properties can consume excessive CPU time and heap memory and
| terminate or stall a service. This issue is fixed in version 7.2.2.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-77399
https://www.cve.org/CVERecord?id=CVE-2026-77399
[1] https://github.com/collective/icalendar/security/advisories/GHSA-qjcq-q7h7-r74v
[2] https://github.com/collective/icalendar/commit/157f85137c65565a308bbcf4fdcc7d8ebce01267

Regards,
Salvatore