Description
vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions of tiny records to exhaust process memory and terminate the API service.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Resource exhaustion causing denial of service
Action: Upgrade Required
AI Analysis

Impact

The vulnerability arises from the POST /api/v2/migration/csv/migrate endpoint in vikunja, which processes CSV uploads without limiting the number of parsed rows. This missing cardinality check allows an authenticated attacker to submit a multipart CSV containing millions of tiny records, causing the API process to consume excessive memory and ultimately terminate, resulting in service denial. The flaw is classified as a Resource Exhaustion vulnerability (CWE‑400).

Affected Systems

The issue exists in all releases of the go‑vikunja:vikunja product line before version 2.6.0. No earlier patch releases address the problem, so the only safe state is to upgrade to version 2.6.0 or newer.

Risk and Exploitability

The CVSS score of 7.1 places this vulnerability in the high‑severity range, and the not listed in the CISA KEV catalog. The EPSS score of less than 1% indicates a very low likelihood of exploitation. The flaw requires authenticated access; attackers must have valid user credentials to invoke the migration endpoint, which is typically used for administrative tasks. Once authenticated, the attacker can easily trigger excessive memory consumption, leading to service disruption.

Generated by OpenCVE AI on September 20, 2026 at 16:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to vikunja version 2.6.0 or later to add the missing cardinality check
  • If an upgrade cannot be applied immediately, temporarily disable the /api/v2/migration/csv/migrate endpoint to block exploitation
  • Configure application‑level rate limiting or memory limits on the migration endpoint until the vulnerability is patched

Generated by OpenCVE AI on September 20, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Go-vikunja
Go-vikunja vikunja
Vendors & Products Go-vikunja
Go-vikunja vikunja

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions of tiny records to exhaust process memory and terminate the API service.
Title vikunja before 2.6.0 Resource Exhaustion via CSV Migration
First Time appeared Vikunja
Vikunja vikunja
Weaknesses CWE-400
CPEs cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
Vendors & Products Vikunja
Vikunja vikunja
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Go-vikunja Vikunja
Vikunja Vikunja
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:28:14.545Z

Reserved: 2026-09-15T11:09:54.872Z

Link: CVE-2026-91969

cve-icon Vulnrichment

Updated: 2026-09-17T19:16:23.327Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:53.647

Modified: 2026-09-17T20:18:54.533

Link: CVE-2026-91969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption