MEDIUM

CVE-2026-91979

2026-09-15 CVSS v3.1
CVSS
6.5

Description

Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausting server resources and crashing the instance.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

0.34%
Probability of exploitation in next 30 days
27.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE