icalendar
icalendar.rb main repository
Activity
- Latest release
- 1mo ago
- Total releases
- 71
- Cadence
- ~2 months
- Last 12 months
- 4
Reach
- Downloads
- 79.3M
- Stars
- 1.2k
Details
- License
- BSD-2-Clause OR unknown
- First release
- Jun 12, 2005
| Version | Released | |
|---|---|---|
2.12.4
patch
|
2.12.4
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.12.3
patch
|
2.12.3
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.12.2
patch
|
2.12.2
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.12.1
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.12.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.12.0
minor
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.12.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.11.2
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.11.2
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.11.1
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.11.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.11.0
minor
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.11.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.10.3
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.10.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.10.2
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.10.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.10.1
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.10.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.10.0
minor
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.10.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.9.0
minor
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.9.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.8.0
minor
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.8.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.7.1
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.7.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.7.0
minor
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.7.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.6.1
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.6.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.6.0
minor
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.6.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.5.3
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.5.3
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.5.2
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.5.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.5.1
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.5.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.5.0
minor
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.5.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.4.1
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.3.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.2.2
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.2.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.2.1
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.2.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.2.0
minor
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.2.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.1.2
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.1.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.1.1
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.1.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.1.0
minor
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.1.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.0.1
patch
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.0.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.5.4
patch
| ||
2.0.0
major
1 CVE
CVE-2026-33635
GHSA-pv9c-9mfh-hvxq
Mar 24, 2026
iCalendar has ICS injection via unsanitized URI property values
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
Low
None
Summary.ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. Details
Relevant code:
PoCRun the following with the library loaded:
output:
ImpactApplications that generate FixReject raw CR and LF characters in Affected versions
2.0.0
2.0.1
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
+ 18 more Show less
2.12.0
2.12.1
2.2.0
2.2.1
2.2.2
2.3.0
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.9.0
Fixed in
2.12.2
References
Updated Mar 27, 2026 · Source: OSV.dev |
2.0.0
major
Dependencies (8)
Changelog
Compare changes
|
|
1.5.3
patch
| ||
2.0.0.beta.2
pre
| ||
2.0.0.beta.1
pre
| ||
1.5.2
patch
| ||
1.5.1
patch
| ||
1.5.0
minor
| ||
1.4.5
patch
| ||
1.4.4
patch
| ||
1.4.3
patch
| ||
1.4.2
patch
| ||
1.4.1
patch
| ||
1.4.0
minor
| ||
1.3.0
minor
| ||
1.2.4
patch
| ||
1.2.3
patch
| ||
1.2.2
patch
|