๐Ÿ” CVE Alert

CVE-2026-55247

CRITICAL 9.1

plone.app.event: Denial of service via iCalendar import

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events, and commits work per event. A logged-in editor can make the server request internal network resources or local calendar files, exhaust resources and take the site offline, and store a malicious event URL that executes script in another user's browser. The fix restricts accepted URLs, applies MAXIMUM_ICAL_IMPORT_SIZE_BYTES and MAXIMUM_ICAL_IMPORT_EVENTS limits, uses transaction savepoints, and validates event URLs. This issue is fixed in versions 5.2.4 and 6.0.1.

CWE CWE-400
Vendor plone
Product plone.app.event
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for plone plone.app.event

Be the first to know when new critical vulnerabilities affecting plone plone.app.event are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
High

Affected Versions

plone / plone.app.event
< 5.2.4 >= 6.0.0, < 6.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/plone/plone.app.event/security/advisories/GHSA-r82h-mqw3-fc56 github.com: https://github.com/plone/plone.app.event/commit/1e3c83c15a24d1a789cdb012593505bc5620e28e github.com: https://github.com/plone/plone.app.event/commit/4de5eb3ea9e4f7f1781622e6d64fc086629d1437 github.com: https://github.com/plone/plone.app.event/releases/tag/5.2.4 github.com: https://github.com/plone/plone.app.event/releases/tag/6.0.1