Impact
The vulnerability allows authenticated attackers to submit requests with deeply nested filter expressions to the task-filter endpoint of Vikunja, exhausting memory and terminating the to legitimate users. The flaw is a classic case CWE-674, and results in a significant service disruption that could affect application availability and reliability. The impact but can render the entire system non‑responsive to authenticated users while the process is crashing or restarting.
Affected Systems
Vikunja applications running any release prior to version 2.6.0 are affected. The official CNA indicates the vulnerability exists in all builds of the product before this release, regardless of deployment environment. Administrators should verify the installed version against the vendor’s release notes to confirm presence of the flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity, and the EPSS score of < 1% indicates a very low probability of exploitation. The lack of a KEV listing suggests that large‑scale exploitation has not yet been observed. The attack requires authenticated access and a carefully crafted request containing thousands of nested parentheses, implying a low‑to‑moderate attack complexity but a high impact if successful. Nonetheless, given the potential for a full denial of service, the vulnerability warrants prompt remediation.
OpenCVE Enrichment