Unbounded Image Decoding Vulnerability in Vikunja Task Management Platform
CVE-2026-33474
6.5MEDIUM
What is CVE-2026-33474?
Vikunja, an open-source self-hosted task management platform, has a vulnerability that stems from unbounded image decoding and resizing during the preview generation process. This weakness allows attackers to exploit the system by sending highly compressed images with excessively large dimensions, leading to potential exhaustion of CPU resources and memory. To mitigate this risk, it is essential for users running versions prior to 2.2.0 to upgrade to 2.2.0 or later, where the issue has been addressed.
Affected Version(s)
vikunja >= 1.0.0-rc0, < 2.2.0
