CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-55099

highCVSS 7.5covered by 2 sourcesfirst seen 2026-08-25
Summary Component.eq compares subcomponents in O(2^n) time relative to nesting depth. Because the parser accepts arbitrarily nested components, a sub-kilobyte .ics file is enough to make a single equality check run for minutes or hang indefinitely. Any application that compares parsed components (==, !=, in, set/dict membership, deduplication, test assertions) against attacker-supplied calendar data is exposed to denial of service. Details Component subclasses dict and stores children in a separate subcomponents list. eq (src/icalendar/cal/component.py:642-665) checks set-equivalence of children with two membership loops: def eq(self, other): if len(self.subcomponents) != len(other.subcomponents): return False if not super().eq(other): return False for subcomponent in self.subcomponents: if subcomponent not in other.subcomponents: return False for subcomponent in other.subcomponents: if subcomponent not in self.subcomponents: return False return True Each ... not in ... test invokes eq on the children. For a nested chain, both loops descend the full subtree, so each level spawns two recursive comparisons: T(n) = 2·T(n-1) → O(2^n). Parsing does not gate this. Component.from_ical builds the structure iteratively and imposes no depth limit, so BEGIN:VEVENT blocks can be nested to any depth (parsing the payload below is instant). The cost is paid only when a comparison occurs, and only when the operands are equal far enough down to keep both loops recursing, a condition the attacker controls by submitting equal subtrees. PoC from icalendar import Calendar d = 26 event = b"BEGIN:VEVENT\r\n" * d + b"END:VEVENT\r\n" * d ics = b"BEGIN:VCALENDAR\r\n" + event + event + b"END:VCALENDAR\r\n" cal = Calendar.from_ical(ics) a, b = cal.subcomponents a == b Measured on icalendar 7.1.x, CPython 3.14: | Payload | Depth | == time | |---|---|---| | 552 B | 20 | 0.76 s | | 656 B | 24 | 12 s | | 708 B | 26 | 48 s | | ~800 B | 30 | ~13 min | A single uploaded file supplies bot

⚡ Watch CVE-2026-55099

Get an email if CVE-2026-55099 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-55099

CVE.org record

Embed the live status

CVE-2026-55099 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-55099 status](https://www.csirts.com/badge/CVE-2026-55099)](https://www.csirts.com/cve/CVE-2026-55099)