GHSA-p4h8-xg7f-xqrcHigh· 6.5▾ TwilightDuplicate Advisory: Vikunja: Denial of service via decompression bomb in the data import
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-w7jp-mf2v-8342. This link is maintained to preserve external references.
Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausting server resources and crashing the instance.
github.com/go-vikunja/vikunja <= 2.5.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-91979Medium· 6.5Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service
GHSA-m4vj-wr5q-cmvrHigh· 7.5Duplicate Advisory: Vikunja: Every /api/v2 pre-auth endpoint is unthrottled on a stock install while its /api/v1 twin is rate limited
CVE-2026-91969Medium· 6.5vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality
CVE-2026-91971Medium· 6.5Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts
CVE-2021-37136High· 7.5The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression)
CVE-2021-37137High· 7.5The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage