Description
Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts. Attackers can upload small images with extreme aspect ratios that consume significant CPU and memory during processing, causing denial of service through repeated or concurrent uploads.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Vikunja0 does not enforce pixel‑decode limits on avatar and project‑background uploads, letting authenticated users submit images that expand to extremely large decoded pixel counts. The server then expends disproportionate CPU and memory during image processing, leading to significant slowdown or crashes when uploads are repeated or made concurrently. The effect is a denial‑of‑service that impacts all users of the affected instance.

Affected Systems

Vikunja instances running any release prior to v2.6.0. The product is identified by the vendor name go‑vikunja and the product name Vikunja. Versions 2.6.0 and newer incorporate the pixel‑limit mitigation and are no longer vulnerable.

Risk and Exploitability

The CVSS score of 7.1 categorizes this vulnerability as high severity. The EPSS score is reported as less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA attack vector requires an authenticated user to upload images, the potential for a successful exploit depends on access control measures. If authentication is compromised or misused, an attacker can trigger resource exhaustion and cause a denial‑of‑service condition for all users.

Generated by OpenCVE AI on September 20, 2026 at 16:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Vikunja to version later to apply the pixel‑size limiter that eliminates the flaw.
  • If an upgrade is not immediately possible, disable or restrict avatar and project‑background uploads via the application configuration to reduce attack surface.
  • Configure server‑level resource limits such as cgroups or container quotas to limit CPU and memory usage per process, mitigating the impact of a potential denial‑of‑service attack.

Generated by OpenCVE AI on September 20, 2026 at 16:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Go-vikunja
Go-vikunja vikunja
Vendors & Products Go-vikunja
Go-vikunja vikunja

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts. Attackers can upload small images with extreme aspect ratios that consume significant CPU and memory during processing, causing denial of service through repeated or concurrent uploads.
Title Vikunja before 2.6.0 Denial of Service via Avatar Upload
First Time appeared Vikunja
Vikunja vikunja
Weaknesses CWE-400
CPEs cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
Vendors & Products Vikunja
Vikunja vikunja
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Go-vikunja Vikunja
Vikunja Vikunja
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T18:48:39.833Z

Reserved: 2026-09-15T11:09:54.873Z

Link: CVE-2026-91971

cve-icon Vulnrichment

Updated: 2026-09-21T18:48:15.765Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:53.947

Modified: 2026-09-21T19:17:16.073

Link: CVE-2026-91971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption