{"id":"GHSA-p4h8-xg7f-xqrc","title":"Duplicate Advisory: Vikunja: Denial of service via decompression bomb in the data import","summary":"Duplicate Advisory: Vikunja: Denial of service via decompression bomb in the data import","severity":"high","cvss":6.5,"cwe":["CWE-400"],"vendor":"go-vikunja","product":"github.com/go-vikunja/vikunja","ecosystem":"go","affected":["github.com/go-vikunja/vikunja <= 2.5.0"],"published":"2026-09-15","updated":"2026-10-09","sourceUpdated":"2026-10-09T20:52:46Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-p4h8-xg7f-xqrc","references":[{"url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-w7jp-mf2v-8342"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91979"},{"url":"https://www.vulncheck.com/advisories/vikunja-before-2.6.0-denial-of-service-via-decompression-bomb"},{"url":"https://github.com/advisories/GHSA-p4h8-xg7f-xqrc"}],"tags":["ghsa","go"],"ingestedAt":"2026-10-09T21:12:42.328Z","slug":"GHSA-p4h8-xg7f-xqrc","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-w7jp-mf2v-8342. This link is maintained to preserve external references.\n\n### Original Description\nVikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausting server resources and crashing the instance.\n\n## Affected packages\n\n- `github.com/go-vikunja/vikunja <= 2.5.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}