GHSA-m4vj-wr5q-cmvrHigh· 7.5▾ TwilightDuplicate Advisory: Vikunja: Every /api/v2 pre-auth endpoint is unthrottled on a stock install while its /api/v1 twin is rate limited
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-6rvj-qwjf-3m4q. This link is maintained to preserve external references.
Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes. Remote unauthenticated attackers can perform unbounded credential guessing, account enumeration, and password-reset flooding attacks without throttling restrictions.
github.com/go-vikunja/vikunja <= 2.5.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-91972High· 7.5Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes
GHSA-p4h8-xg7f-xqrcHigh· 6.5Duplicate Advisory: Vikunja: Denial of service via decompression bomb in the data import
CVE-2026-91973High· 7.5Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection
CVE-2025-12547Low· 3.7A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1
CVE-2025-66204High· 8.1WBCE CMS is a content management system
CVE-2026-91969Medium· 6.5vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality