Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Go-vikunja
Go-vikunja vikunja |
|
| Vendors & Products |
Go-vikunja
Go-vikunja vikunja |
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and terminate the API process. | |
| Title | vikunja before 2.6.0 Denial of Service via unbounded filter recursion | |
| First Time appeared |
Vikunja
Vikunja vikunja |
|
| Weaknesses | CWE-674 | |
| CPEs | cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vikunja
Vikunja vikunja |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:56:07.929Z
Reserved: 2026-09-15T11:08:44.670Z
Link: CVE-2026-91968
Updated: 2026-09-15T15:55:54.060Z
Status : Received
Published: 2026-09-15T16:17:53.093
Modified: 2026-09-15T16:17:53.093
Link: CVE-2026-91968
No data.
OpenCVE Enrichment
Updated: 2026-09-15T22:30:14Z