icalendar is vulnerable to Denial of Service (DoS)
55
Medium Risk
Icalendar::Calendar.parse recurses once for every BEGIN: line in an .ics input with no limit on nesting depth. A calendar with a few thousand nested components exhausts the Ruby call stack and raises SystemStackError, which does not inherit from StandardError so a caller's rescue => e around the parse does not catch it and the request aborts. This affects applications that hand untrusted calendar data (uploaded invites, subscribed feeds, mail attachments) to the parser without their own size or nesting limit. The fix tracks nesting depth in parse_component and raises a normal ParseError once a configurable depth limit (default 5) is exceeded.
You are affected if you are using a version that falls within the vulnerable range and you parse .ics calendar data from an untrusted source.
icalendar is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 2.12.4.
Upgrade the icalendar library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.