Impact
Vikunja0 does not enforce pixel‑decode limits on avatar and project‑background uploads, letting authenticated users submit images that expand to extremely large decoded pixel counts. The server then expends disproportionate CPU and memory during image processing, leading to significant slowdown or crashes when uploads are repeated or made concurrently. The effect is a denial‑of‑service that impacts all users of the affected instance.
Affected Systems
Vikunja instances running any release prior to v2.6.0. The product is identified by the vendor name go‑vikunja and the product name Vikunja. Versions 2.6.0 and newer incorporate the pixel‑limit mitigation and are no longer vulnerable.
Risk and Exploitability
The CVSS score of 7.1 categorizes this vulnerability as high severity. The EPSS score is reported as less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA attack vector requires an authenticated user to upload images, the potential for a successful exploit depends on access control measures. If authentication is compromised or misused, an attacker can trigger resource exhaustion and cause a denial‑of‑service condition for all users.
OpenCVE Enrichment