---
id: GHSA-jfw3-2gcf-23r5
title: >-
  Duplicate Advisory: Vikunja: Unbounded nested task-filter recursion permits
  API process termination
summary: >-
  Duplicate Advisory: Vikunja: Unbounded nested task-filter recursion permits
  API process termination
severity: high
cvss: 6.5
cwe:
  - CWE-674
vendor: api
product: code.vikunja.io/api
ecosystem: go
affected:
  - code.vikunja.io/api = 2.5.0
published: '2026-09-15'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T20:52:57Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-jfw3-2gcf-23r5'
references:
  - url: >-
      https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xxc3-xpmc-vmvr
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91968'
  - url: >-
      https://www.vulncheck.com/advisories/vikunja-before-2.6.0-denial-of-service-via-unbounded-filter-recursion
  - url: 'https://github.com/advisories/GHSA-jfw3-2gcf-23r5'
tags:
  - ghsa
  - go
ingestedAt: '2026-10-09T21:12:42.327Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-xxc3-xpmc-vmvr. This link is maintained to preserve external references.

### Original Description
vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and terminate the API process.

## Affected packages

- `code.vikunja.io/api = 2.5.0`

## Remediation

Refer to the advisory for the patched release.
