Unbounded Image Decoding Vulnerability in Vikunja Task Management Platform
CVE-2026-33474

6.5MEDIUM

Key Information:

Vendor

Go-vikunja

Status
Vendor
CVE Published:
24 March 2026

What is CVE-2026-33474?

Vikunja, an open-source self-hosted task management platform, has a vulnerability that stems from unbounded image decoding and resizing during the preview generation process. This weakness allows attackers to exploit the system by sending highly compressed images with excessively large dimensions, leading to potential exhaustion of CPU resources and memory. To mitigate this risk, it is essential for users running versions prior to 2.2.0 to upgrade to 2.2.0 or later, where the issue has been addressed.

Affected Version(s)

vikunja >= 1.0.0-rc0, < 2.2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.