vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and terminate the API process.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 16:17
Updated : 2026-09-15 16:17
NVD link : CVE-2026-91968
Mitre link : CVE-2026-91968
CVE.ORG link : CVE-2026-91968
JSON object : View
Products Affected
No product.
CWE
CWE-674
Uncontrolled Recursion
