Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-59045

Опубликовано: 10 сент. 2025
Источник: nvd
EPSS Низкий

Описание

Stalwart is a mail and collaboration server. Starting in version 0.12.0 and prior to version 0.13.3, a memory exhaustion vulnerability exists in Stalwart's CalDAV implementation that allows authenticated attackers to cause denial-of-service by triggering unbounded memory consumption through recurring event expansion. An authenticated attacker can crash the Stalwart server by creating recurring events with large payloads and triggering their expansion through CalDAV REPORT requests. A single malicious request expanding 300 events with 1000-character descriptions can consume up to 2 GB of memory. The vulnerability exists in the ArchivedCalendarEventData.expand function, which processes CalDAV REPORT requests with event expansion. When a client requests recurring events in their expanded form using the <C:expand> element, the server stores all expanded event instances in memory without enforcing size limits. Users should upgrade to Stalwart version 0.13.3 or later to receive a fix.

EPSS

Процентиль: 17%
0.00054
Низкий

Дефекты

CWE-770

Связанные уязвимости

debian
5 месяцев назад

Stalwart is a mail and collaboration server. Starting in version 0.12. ...

EPSS

Процентиль: 17%
0.00054
Низкий

Дефекты

CWE-770