Resource Exhaustion Vulnerability in Vikunja by Go Vikunja
CVE-2026-91969
7.1HIGH
What is CVE-2026-91969?
Vikunja versions prior to 2.6.0 are susceptible to a resource exhaustion vulnerability via the POST /api/v2/migration/csv/migrate endpoint. This flaw allows authenticated attackers to upload multipart CSV files containing a huge number of tiny records, leading to excessive memory consumption and potential termination of the API service. This vulnerability underscores the importance of implementing strict validation and limits on input data to prevent such resource-depleting attacks.
Affected Version(s)
vikunja 2.5.0 < 2.6.0
vikunja 2.6.0
