THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-r82h-mqw3-fc56 (critical) — plone.app.event vulnerable to denial of service via iCalendar import

[GHSA] GHSA-r82h-mqw3-fc56 (critical) — plone.app.event vulnerable to denial of service via iCalendar import

medgithub_advisoriesPublished 2026-08-28

GHSA-r82h-mqw3-fc56 Severity: critical CVE: CVE-2026-55247

plone.app.event vulnerable to denial of service via iCalendar import

### Impact By abusing the iCalendar import functionality, a logged-in editor could take the whole site offline, make the server reach into the internal network and read calendar files off disk (SSRF), and store XSS.

### Patches The problem has been patched in `plone.ap

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-r82h-mqw3-fc56