Impact
The vulnerability arises from the POST /api/v2/migration/csv/migrate endpoint in vikunja, which processes CSV uploads without limiting the number of parsed rows. This missing cardinality check allows an authenticated attacker to submit a multipart CSV containing millions of tiny records, causing the API process to consume excessive memory and ultimately terminate, resulting in service denial. The flaw is classified as a Resource Exhaustion vulnerability (CWE‑400).
Affected Systems
The issue exists in all releases of the go‑vikunja:vikunja product line before version 2.6.0. No earlier patch releases address the problem, so the only safe state is to upgrade to version 2.6.0 or newer.
Risk and Exploitability
The CVSS score of 7.1 places this vulnerability in the high‑severity range, and the not listed in the CISA KEV catalog. The EPSS score of less than 1% indicates a very low likelihood of exploitation. The flaw requires authenticated access; attackers must have valid user credentials to invoke the migration endpoint, which is typically used for administrative tasks. Once authenticated, the attacker can easily trigger excessive memory consumption, leading to service disruption.
OpenCVE Enrichment