THREAT OPS › Threat News › [GHSA] GHSA-r82h-mqw3-fc56 (critical) — plone.app.event vulnerable to denial of service via iCalendar import
[GHSA] GHSA-r82h-mqw3-fc56 (critical) — plone.app.event vulnerable to denial of service via iCalendar import
GHSA-r82h-mqw3-fc56 Severity: critical CVE: CVE-2026-55247
plone.app.event vulnerable to denial of service via iCalendar import
### Impact By abusing the iCalendar import functionality, a logged-in editor could take the whole site offline, make the server reach into the internal network and read calendar files off disk (SSRF), and store XSS.
### Patches The problem has been patched in `plone.ap
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-55247cve
- security@plone.orgemail
Original source: https://github.com/advisories/GHSA-r82h-mqw3-fc56