GHSA-c2g7-39fr-cp8qHigh· 6.5▾ TwilightDuplicate Advisory: Vikunja: Planka migration retains an unbounded aggregate of attacker-served attachments and can OOM the API
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-wq92-8x3r-fm38. This link is maintained to preserve external references.
Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests pointing to attacker-controlled servers advertising numerous size-compliant attachments, exhausting worker memory and causing denial of service for all users.
code.vikunja.io/api >= 2.5.0, < 2.6.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-9jrx-vmh8-c6xwHigh· 8.1Duplicate Advisory: Vikunja: Link-share principal ID collision allows cross-account API token issuance and management
CVE-2026-57458High· 8.1Vikunja is an open-source self-hosted task management platform
GHSA-p4r4-8cxw-pjx7Critical· 6.5Duplicate Advisory: Vikunja: Link-share token reads any tenant's kanban buckets and enumerates usernames/IDs instance-wide (BOLA)
GHSA-9xwc-vwww-qqmwHigh· 7.5Duplicate Advisory: Vikunja: Link-share principal-type confusion enables cross-account team removal, bot takeover, and roster disclosure
CVE-2026-62367HighVikunja is an open-source self-hosted task management platform
CVE-2026-62376High· 8.1Vikunja is an open-source self-hosted task management platform