Description
Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests pointing to attacker-controlled servers advertising numerous size-compliant attachments, exhausting worker memory and causing denial of service for all users.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Resource Exhaustion
Action: Apply Patch
AI Analysis

Impact

Vikunja versions prior to 2.6.0 contain a flaw in the Planka migration helper that fails to enforce aggregate memory budgets during migration processes. An authenticated attacker can submit a migration request that points to a malicious server offering many size‑compliant attachments, which leads the worker to allocate more memory than allowed. The result is a memory exhaustion that degrades or halts the worker service, denying all users access to the application.

Affected Systems

The vulnerability affects the Vikunja open‑source project (go‑vikunja:vikunja) across all versions before 2.6.0. Users running any pre‑2.6.0 release on any platform are impacted until they upgrade to the patched version.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity flaw. Exploitation requires legitimate a authenticated attacker with user privileges. The EPSS score of < 1% suggests a very low probability of exploitation, and the lack of a KEV listing further indicates no currently documented exploit activity. The attack vector is inferred to be local or remote authenticated users capable of invoking the migration API, as the description states that attackers can submit migration requests. Because the flaw manifests as a denial of service, its impact includes service disruption and potential business downtime.

Generated by OpenCVE AI on September 20, 2026 at 16:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Vikunja to version 2.6.0 or later, which includes the memory budget enforcement fix.
  • Limit or disable the Planka migration feature for untrusted or external sources, or ensure that migration endpoints can only point to validated, trusted servers.
  • Configure system resource limits for migration workers and monitor memory usage so that a runaway migration will be terminated before affecting other users.

Generated by OpenCVE AI on September 20, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Go-vikunja
Go-vikunja vikunja
Vendors & Products Go-vikunja
Go-vikunja vikunja

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests pointing to attacker-controlled servers advertising numerous size-compliant attachments, exhausting worker memory and causing denial of service for all users.
Title Vikunja before 2.6.0 Resource Exhaustion via Planka Migration
First Time appeared Vikunja
Vikunja vikunja
Weaknesses CWE-770
CPEs cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
Vendors & Products Vikunja
Vikunja vikunja
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Go-vikunja Vikunja
Vikunja Vikunja
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T16:02:52.721Z

Reserved: 2026-09-15T11:09:54.873Z

Link: CVE-2026-91970

cve-icon Vulnrichment

Updated: 2026-09-15T16:02:49.410Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:53.803

Modified: 2026-09-16T19:49:18.987

Link: CVE-2026-91970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling