CVE-2025-59045 - CVE House
Back to Database
Status published High CVE-2025-59045

Stalwart vulnerable to Memory Exhaustion via CalDAV Event Expansion

Vulnerability Description

Stalwart is a mail and collaboration server. Starting in version 0.12.0 and prior to version 0.13.3, a memory exhaustion vulnerability exists in Stalwart's CalDAV implementation that allows authenticated attackers to cause denial-of-service by triggering unbounded memory consumption through recurring event expansion. An authenticated attacker can crash the Stalwart server by creating recurring events with large payloads and triggering their expansion through CalDAV REPORT requests. A single malicious request expanding 300 events with 1000-character descriptions can consume up to 2 GB of memory. The vulnerability exists in the `ArchivedCalendarEventData.expand` function, which processes CalDAV `REPORT` requests with event expansion. When a client requests recurring events in their expanded form using the `<C:expand>` element, the server stores all expanded event instances in memory without enforcing size limits. Users should upgrade to Stalwart version 0.13.3 or later to receive a fix. If immediate upgrading is not possible, implement memory limits at the container/system level; monitor server memory usage for unusual spikes; consider rate limiting CalDAV REPORT requests; and restrict CalDAV access to trusted users only.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59045

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

stalwartlabs

View all reports →

Affected Software

stalwart
Vulnerable Versions:
>= 0.12.0, < 0.13.3

Timeline

Official Publish: September 10th, 2025
Last Modified: September 11th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)