Beveiligingsadvies

CVE-2026-91969

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-15 15:18:20
Laatst bijgewerkt 2026-09-15 15:18:20
Toegewezen door VulnCheck
CVSS-score 7.1
Status PUBLISHED

Beschrijving

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions of tiny records to exhaust process memory and terminate the API service.