Radicale is a lightweight, open-source calendar and contact server that provides CalDAV and CardDAV protocol support for synchronizing personal data across devices; its compact scope and specialized function means vulnerabilities are concentrated in a single product. The durable signal in its disclosure history centers on concurrency and input-handling issues, including race conditions in shared-resource access and improper input validation, which reflect the synchronization and protocol-parsing demands of a networked personal-information server. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Radicale over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-1505CRITICAL The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted path, as demonstrated by /c:/file/ignore. | Feb 3, 2016 | 10.0 | 30 | NO | NO |
CVE-2017-8342HIGH Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method. | Apr 30, 2017 | 8.1 | 28 | NO | NO |
CVE-2015-8747CRITICAL The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name. | Feb 3, 2016 | 10.0 | 25 | NO | NO |
CVE-2015-8748MEDIUM Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user name, as demonstrated by ".*". | Feb 3, 2016 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Radicale.
Media articles that mention a CVE ID that affects a product developed by Radicale — matched by CVE ID, not by vendor name.