vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions of tiny records to exhaust process memory and terminate the API service.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions of tiny records to exhaust process memory and terminate the API service. | |
| Title | vikunja before 2.6.0 Resource Exhaustion via CSV Migration | |
| First Time appeared |
Vikunja
Vikunja vikunja |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vikunja
Vikunja vikunja |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:18:20.780Z
Reserved: 2026-09-15T11:09:54.872Z
Link: CVE-2026-91969
No data.
Status : Received
Published: 2026-09-15T16:17:53.647
Modified: 2026-09-15T16:17:53.647
Link: CVE-2026-91969
No data.
OpenCVE Enrichment
No data.
Weaknesses