Impact
Vikunja, before version 2.6.0, does not restrict the expansion of archives that are imported by users. An attacker can create a highly compressed file that, when decompressed by the application, expands into tens gigabytes of data in memory and on disk. This uncontrolled growth can exhaust server resources, causing the service to become unresponsive or crash, thereby achieving a denial of service.
Affected Systems
The vulnerability affects the Vikunja application, any instance running a version earlier than 2.6.0. Users who are authenticated in the system can upload the malicious archive during the import process.
Risk and Exploitability
The severity of the issue is reflected in a CVSS score of 7.1, indicating a moderately high potential impact. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Attackers need only to be authenticated to the application; the flaw allows them to upload a specific file type that triggers massive unbounded decompression. Once the attuned archive is processed, the server’s memory and disk resources are consumed, leading to service disruption.
OpenCVE Enrichment