PT-2026-92093 · Vikunja · Vikunja

·

CVE-2026-91979

·

Published

2026-09-15

·

Updated

2026-09-15

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vikunja versions prior to 2.6.0
Description Authenticated users can cause a denial of service during data import because the system fails to limit archive expansion. An attacker can upload highly compressed files that expand to tens of gigabytes in memory and on disk, which exhausts server resources and crashes the instance.
Recommendations Update to version 2.6.0 or later.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91979
GHSA-W7JP-MF2V-8342

Affected Products

Vikunja