Impact
Vikunja versions prior to 2.6.0 contain a flaw in the Planka migration helper that fails to enforce aggregate memory budgets during migration processes. An authenticated attacker can submit a migration request that points to a malicious server offering many size‑compliant attachments, which leads the worker to allocate more memory than allowed. The result is a memory exhaustion that degrades or halts the worker service, denying all users access to the application.
Affected Systems
The vulnerability affects the Vikunja open‑source project (go‑vikunja:vikunja) across all versions before 2.6.0. Users running any pre‑2.6.0 release on any platform are impacted until they upgrade to the patched version.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity flaw. Exploitation requires legitimate a authenticated attacker with user privileges. The EPSS score of < 1% suggests a very low probability of exploitation, and the lack of a KEV listing further indicates no currently documented exploit activity. The attack vector is inferred to be local or remote authenticated users capable of invoking the migration API, as the description states that attackers can submit migration requests. Because the flaw manifests as a denial of service, its impact includes service disruption and potential business downtime.
OpenCVE Enrichment