---
id: CVE-2026-91979
title: >-
  Vikunja before 2.6.0 fails to limit archive expansion during data import,
  allowing authenticated users to cause denial of service
summary: >-
  Vikunja before 2.6.0 fails to limit archive expansion during data import,
  allowing authenticated users to cause denial of service. Attackers can upload
  highly compressed files that expand to tens of gigabytes in memory and disk,
  exhausti…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
vendor: go-vikunja
product: vikunja
affected:
  - vikunja < 2.6.0
published: '2026-09-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T20:18:54.653'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91979'
references:
  - url: >-
      https://github.com/go-vikunja/vikunja/security/advisories/GHSA-w7jp-mf2v-8342
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/vikunja-before-2.6.0-denial-of-service-via-decompression-bomb
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T19:16:24.646410Z'
epss: 0.00436
epssPercentile: 0.35226
ingestedAt: '2026-09-15T15:39:12.911Z'
---

## Overview

Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausting server resources and crashing the instance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
