vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions of tiny records to exhaust process memory and terminate the API service.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 16:17
Updated : 2026-09-15 16:17
NVD link : CVE-2026-91969
Mitre link : CVE-2026-91969
CVE.ORG link : CVE-2026-91969
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption
