Description
Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausting server resources and crashing the instance.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Vikunja, before version 2.6.0, does not restrict the expansion of archives that are imported by users. An attacker can create a highly compressed file that, when decompressed by the application, expands into tens gigabytes of data in memory and on disk. This uncontrolled growth can exhaust server resources, causing the service to become unresponsive or crash, thereby achieving a denial of service.

Affected Systems

The vulnerability affects the Vikunja application, any instance running a version earlier than 2.6.0. Users who are authenticated in the system can upload the malicious archive during the import process.

Risk and Exploitability

The severity of the issue is reflected in a CVSS score of 7.1, indicating a moderately high potential impact. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Attackers need only to be authenticated to the application; the flaw allows them to upload a specific file type that triggers massive unbounded decompression. Once the attuned archive is processed, the server’s memory and disk resources are consumed, leading to service disruption.

Generated by OpenCVE AI on September 20, 2026 at 16:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Vikunja to version 2.6.0 or later to apply the official fix for this archiving issue.
  • Configure the application to limit the maximum size of uploaded archives to a safe threshold, preventing excessive memory or disk consumption during import.
  • Implement system resource limits or cgroups to constrain memory and disk usage per instance, reducing impact of potential decompression bombs.

Generated by OpenCVE AI on September 20, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Go-vikunja
Go-vikunja vikunja
Vendors & Products Go-vikunja
Go-vikunja vikunja

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausting server resources and crashing the instance.
Title Vikunja before 2.6.0 Denial of Service via Decompression Bomb
First Time appeared Vikunja
Vikunja vikunja
Weaknesses CWE-400
CPEs cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*
Vendors & Products Vikunja
Vikunja vikunja
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Go-vikunja Vikunja
Vikunja Vikunja
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:28:09.001Z

Reserved: 2026-09-15T11:10:41.353Z

Link: CVE-2026-91979

cve-icon Vulnrichment

Updated: 2026-09-17T19:16:25.742Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:54.793

Modified: 2026-09-17T20:18:54.653

Link: CVE-2026-91979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption