---
id: GHSA-p4h8-xg7f-xqrc
title: >-
  Duplicate Advisory: Vikunja: Denial of service via decompression bomb in the
  data import
summary: >-
  Duplicate Advisory: Vikunja: Denial of service via decompression bomb in the
  data import
severity: high
cvss: 6.5
cwe:
  - CWE-400
vendor: go-vikunja
product: github.com/go-vikunja/vikunja
ecosystem: go
affected:
  - github.com/go-vikunja/vikunja <= 2.5.0
published: '2026-09-15'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T20:52:46Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-p4h8-xg7f-xqrc'
references:
  - url: >-
      https://github.com/go-vikunja/vikunja/security/advisories/GHSA-w7jp-mf2v-8342
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91979'
  - url: >-
      https://www.vulncheck.com/advisories/vikunja-before-2.6.0-denial-of-service-via-decompression-bomb
  - url: 'https://github.com/advisories/GHSA-p4h8-xg7f-xqrc'
tags:
  - ghsa
  - go
ingestedAt: '2026-10-09T21:12:42.328Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-w7jp-mf2v-8342. This link is maintained to preserve external references.

### Original Description
Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausting server resources and crashing the instance.

## Affected packages

- `github.com/go-vikunja/vikunja <= 2.5.0`

## Remediation

Refer to the advisory for the patched release.
