Denial of Service Vulnerability in Vikunja Product by Vikunja
CVE-2026-91971
7.1HIGH
What is CVE-2026-91971?
Vikunja versions prior to 2.6.0 have a vulnerability that allows authenticated users to exploit avatar and project background upload endpoints. By bypassing pixel decode limits, attackers can upload images with extreme aspect ratios, leading to excessive CPU and memory consumption during processing. This can result in denial of service due to repeated or concurrent uploads, severely impacting system performance and availability.
Affected Version(s)
vikunja 0 < 2.6.0
vikunja 2.6.0
