CVE-2026-61915: CWE-415 Double Free in cyrusimap Cyrus IMAP
CVE-2026-61915 is a medium severity vulnerability in Cyrus IMAP before version 3.12.4. It involves a double-free memory error triggered by an authenticated calendar user sending a PATCH request with a specific PATCH-ACTION parameter against a resource containing multiple properties of the same kind. This flaw can cause a Cyrus CalDAV worker process to crash due to improper memory management.
AI Analysis
Technical Summary
The vulnerability CVE-2026-61915 affects Cyrus IMAP versions prior to 3.12.4. It is a double-free issue (CWE-415) occurring in the handling of PATCH requests with PATCH-ACTION="BYPARAM@...". When a resource has two or more properties of the matched kind, the memory holding the selector is freed multiple times during iteration, leading to a crash of the Cyrus CalDAV worker process. This requires authenticated access and high attack complexity, with no user interaction needed. The CVSS 3.1 base score is 4.2, indicating medium severity.
Potential Impact
An authenticated calendar user can cause a denial of service by crashing the Cyrus CalDAV worker process through crafted PATCH requests. There is no confidentiality impact, but integrity is slightly affected due to the potential disruption of service. Availability is impacted as the worker process may crash, leading to service interruptions.
Mitigation Recommendations
No official patch or remediation level is currently documented for this vulnerability. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restricting authenticated user permissions or limiting access to the CalDAV service may reduce risk.
CVE-2026-61915: CWE-415 Double Free in cyrusimap Cyrus IMAP
Description
CVE-2026-61915 is a medium severity vulnerability in Cyrus IMAP before version 3.12.4. It involves a double-free memory error triggered by an authenticated calendar user sending a PATCH request with a specific PATCH-ACTION parameter against a resource containing multiple properties of the same kind. This flaw can cause a Cyrus CalDAV worker process to crash due to improper memory management.
CVSS v3.1
Score 4.2medium
Affected software
pkg:github/cyrusimap/cyrus-imapRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-61915 affects Cyrus IMAP versions prior to 3.12.4. It is a double-free issue (CWE-415) occurring in the handling of PATCH requests with PATCH-ACTION="BYPARAM@...". When a resource has two or more properties of the matched kind, the memory holding the selector is freed multiple times during iteration, leading to a crash of the Cyrus CalDAV worker process. This requires authenticated access and high attack complexity, with no user interaction needed. The CVSS 3.1 base score is 4.2, indicating medium severity.
Potential Impact
An authenticated calendar user can cause a denial of service by crashing the Cyrus CalDAV worker process through crafted PATCH requests. There is no confidentiality impact, but integrity is slightly affected due to the potential disruption of service. Availability is impacted as the worker process may crash, leading to service interruptions.
Mitigation Recommendations
No official patch or remediation level is currently documented for this vulnerability. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restricting authenticated user permissions or limiting access to the CalDAV service may reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-07-13T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa1c011acd9273b49d10fab
Added to database: 09/09/2026, 20:22:41 UTC
Last enriched: 09/09/2026, 20:37:54 UTC
Last updated: 09/09/2026, 23:18:30 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.