CVE-2026-91979: Uncontrolled Resource Consumption in go-vikunja vikunja
Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausting server resources and crashing the instance.
AI Analysis
Technical Summary
Vikunja versions prior to 2.6.0 contain an uncontrolled resource consumption vulnerability during the data import process. The software fails to impose limits on archive expansion, allowing authenticated attackers to upload compressed files that decompress into very large sizes, consuming excessive memory and disk space. This results in denial of service conditions by exhausting server resources and causing application crashes. The vulnerability has a CVSS 3.1 base score of 6.5, indicating a medium severity level with network attack vector, low attack complexity, requiring privileges, no user interaction, and causing availability impact only.
Potential Impact
Exploitation of this vulnerability allows authenticated users to cause denial of service by exhausting server memory and disk resources through oversized archive expansion during data import. This leads to application crashes and service unavailability. There is no impact on confidentiality or integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict or monitor authenticated user uploads to prevent large or suspicious archive files that could trigger resource exhaustion.
CVE-2026-91979: Uncontrolled Resource Consumption in go-vikunja vikunja
Description
Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausting server resources and crashing the instance.
CVSS v3.1
Score 6.5medium
Affected software
go-vikunja
vikunja
pkg:golang/github.com/go-vikunja/vikunjaRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Vikunja versions prior to 2.6.0 contain an uncontrolled resource consumption vulnerability during the data import process. The software fails to impose limits on archive expansion, allowing authenticated attackers to upload compressed files that decompress into very large sizes, consuming excessive memory and disk space. This results in denial of service conditions by exhausting server resources and causing application crashes. The vulnerability has a CVSS 3.1 base score of 6.5, indicating a medium severity level with network attack vector, low attack complexity, requiring privileges, no user interaction, and causing availability impact only.
Potential Impact
Exploitation of this vulnerability allows authenticated users to cause denial of service by exhausting server memory and disk resources through oversized archive expansion during data import. This leads to application crashes and service unavailability. There is no impact on confidentiality or integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict or monitor authenticated user uploads to prevent large or suspicious archive files that could trigger resource exhaustion.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-15T11:10:41.353Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa9651c55bf5e2cf502eb27
Added to database: 09/15/2026, 15:32:44 UTC
Last enriched: 09/15/2026, 15:47:33 UTC
Last updated: 09/16/2026, 03:18:47 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.