{"id":"CVE-2026-55247","summary":"plone.app.event: Denial of service via iCalendar import","details":"plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events, and commits work per event. A logged-in editor can make the server request internal network resources or local calendar files, exhaust resources and take the site offline, and store a malicious event URL that executes script in another user's browser. The fix restricts accepted URLs, applies MAXIMUM_ICAL_IMPORT_SIZE_BYTES and MAXIMUM_ICAL_IMPORT_EVENTS limits, uses transaction savepoints, and validates event URLs. This issue is fixed in versions 5.2.4 and 6.0.1.","aliases":["GHSA-r82h-mqw3-fc56"],"modified":"2026-09-02T03:30:29.532033843Z","published":"2026-08-28T18:59:01.212Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-400"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55247.json"},"references":[{"type":"WEB","url":"https://github.com/plone/plone.app.event/releases/tag/5.2.4"},{"type":"WEB","url":"https://github.com/plone/plone.app.event/releases/tag/6.0.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55247.json"},{"type":"ADVISORY","url":"https://github.com/plone/plone.app.event/security/advisories/GHSA-r82h-mqw3-fc56"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55247"},{"type":"FIX","url":"https://github.com/plone/plone.app.event/commit/1e3c83c15a24d1a789cdb012593505bc5620e28e"},{"type":"FIX","url":"https://github.com/plone/plone.app.event/commit/4de5eb3ea9e4f7f1781622e6d64fc086629d1437"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/plone/plone.app.event","events":[{"introduced":"0"},{"introduced":"f77cb42d990b2dcdf0d0c5e9baceb9977713565a"},{"fixed":"67343d3385073c618d37f3835e7575e010fa1ca7"},{"fixed":"0bbaa2f5d32625d5cb895089c7d974c775b36ce6"},{"fixed":"1e3c83c15a24d1a789cdb012593505bc5620e28e"},{"fixed":"4de5eb3ea9e4f7f1781622e6d64fc086629d1437"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"5.2.4"},{"introduced":"6.0.0"},{"fixed":"6.0.1"}]}}],"versions":["6.0.0","5.2.3","5.2.2","5.2.1","5.2.0","5.1.8","5.1.7","5.1.6","5.1.5","5.1.4","5.1.3","5.1.2","5.1.1","5.1.0","5.0.1","5.0.0","4.0.0","4.0.0b1","4.0.0a9","4.0.0a8","4.0.0a7","4.0.0a6","4.0.0a5","4.0.0a4","4.0.0a3","4.0.0a2","4.0.0a1","3.2.10","3.2.9","3.2.8","3.2.7","3.2.6","3.2.5","3.2.4","3.2.3","3.2.2","3.2.1","3.2.0","3.1.1","3.1","3.0.7","3.0.6","3.0.5","3.0.4","3.0.3","3.0.2","3.0.1","3.0","2.0.9","2.0.8","2.0.7","2.0.6","2.0.5","2.0.4","2.0.3","2.0.2","2.0.1","2.0b2","2.0b1","2.0a13","2.0a12","2.0a10","2.0a9","2.0a8","2.0a7","2.0a6","2.0a5","2.0a4","2.0a3","2.0a2","2.0a1","1.1.a1","1.0rc3","1.0rc2","1.0rc1","1.0b8","1.0htug16","1.0htug15","1.0htug13","1.0b6","1.0b5","1.0b4","1.0htug11","1.0b3","1.0htug10","1.0b2","1.0b1","1.0htug9","1.0htug8","1.0htug3","1.0htug2","1.0htug1","1.0a1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55247.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H"}]}