PT-2026-92088 · Vikunja · Vikunja
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
vikunja versions prior to 2.6.0
Description
A resource exhaustion issue exists where the system fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files containing millions of small records to the 'POST /api/v2/migration/csv/migrate' endpoint, leading to process memory exhaustion and termination of the API service.
Recommendations
Update to version 2.6.0 or later.
Restrict access to the 'POST /api/v2/migration/csv/migrate' endpoint to minimize the risk of exploitation.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vikunja