CVE-2026-91969
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Summary
vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions of tiny records to exhaust process memory and terminate the API service.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| go-vikunja | vikunja | 2.5.0 < 2.6.0 | affected |
| go-vikunja | vikunja | 2.6.0 | unaffected |
Weaknesses
- CWE-400: Uncontrolled Resource Consumption
References
- https://github.com/go-vikunja/vikunja/security/advisories/GHSA-pqf9-h8g4-8gmh
- https://www.vulncheck.com/advisories/vikunja-before-2.6.0-resource-exhaustion-via-csv-migration
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.