Radicale before 1.1 allows remote authenticated users to bypass ownerwrite and owneronly limitations via regex metacharacters in the user name, as demonstrated by ".*".
"https://github.com/pypa/advisory-database/blob/main/vulns/radicale/PYSEC-2016-37.yaml"