Intel

AIKIDO-2026-129315

icalendar is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-73xg-gp6q-pw5j Published Yesterday

55

Medium Risk

This Affects:

RUBYicalendar
0.0.1 - 2.12.4
Fixed in 2.12.5
Are you affected? Scan for Free

TL;DR

Icalendar::Calendar.parse recurses once for every BEGIN: line in an .ics input with no limit on nesting depth. A calendar with a few thousand nested components exhausts the Ruby call stack and raises SystemStackError, which does not inherit from StandardError so a caller's rescue => e around the parse does not catch it and the request aborts. This affects applications that hand untrusted calendar data (uploaded invites, subscribed feeds, mail attachments) to the parser without their own size or nesting limit. The fix tracks nesting depth in parse_component and raises a normal ParseError once a configurable depth limit (default 5) is exceeded.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you parse .ics calendar data from an untrusted source.

Background info

icalendar is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 2.12.4.

How to fix this

Upgrade the icalendar library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform