GHSA-69rj-q3v9-vffpHigh· 6.5▾ TwilightDuplicate Advisory: Vikunja: Unbounded image decode on avatar and project-background uploads enables decode/resize amplification
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-4vh2-39rq-rq8j. This link is maintained to preserve external references.
Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts. Attackers can upload small images with extreme aspect ratios that consume significant CPU and memory during processing, causing denial of service through repeated or concurrent uploads.
code.vikunja.io/api <= 2.5.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-55p4-8j34-jv53High· 6.5Duplicate Advisory: Vikunja: Unbounded CSV row cardinality permits API process termination
GHSA-9jrx-vmh8-c6xwHigh· 8.1Duplicate Advisory: Vikunja: Link-share principal ID collision allows cross-account API token issuance and management
CVE-2026-57458High· 8.1Vikunja is an open-source self-hosted task management platform
GHSA-p4r4-8cxw-pjx7Critical· 6.5Duplicate Advisory: Vikunja: Link-share token reads any tenant's kanban buckets and enumerates usernames/IDs instance-wide (BOLA)
GHSA-9xwc-vwww-qqmwHigh· 7.5Duplicate Advisory: Vikunja: Link-share principal-type confusion enables cross-account team removal, bot takeover, and roster disclosure
CVE-2026-62367HighVikunja is an open-source self-hosted task management platform