CVE-2026-91970
moderateAuthenticated memory-exhaustion DoS via Planka migrator in Vikunja < 2.6.0
Vikunja, the self-hosted task-management application, contains a resource exhaustion flaw (CWE-770) in its Planka migrator, which fails to enforce an aggregate memory budget when importing data. An authenticated attacker triggers the bug by submitting a migration request that points to an attacker-controlled Planka server advertising a large number of attachments, each individually within per-file size limits, whose combined in-memory footprint exceeds worker capacity. This exhausts the memory of the Vikunja worker handling migrations, causing a denial of service that affects all users of the instance. All Vikunja deployments before version 2.6.0 are affected, though exploitation requires a valid account and access to the migration feature. The vulnerability is not in CISA's KEV catalog, no public proof of concept is known, and there is no evidence of exploitation in the wild.
What to do: Upgrade Vikunja to version 2.6.0 or later, which enforces aggregate memory budgets during migration jobs. If immediate upgrade is not possible, disable or restrict the Planka migration feature, limit who can create accounts or invoke migrations, and cap container memory so a runaway migration cannot starve the whole instance. Review logs for migration requests referencing unexpected or attacker-controlled Planka server URLs, and monitor worker memory usage during any active migrations.
| Vikunja | before 2.6.0 (< 2.6.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests pointing to attacker-controlled servers advertising numerous size-compliant attachments, exhausting worker memory and causing denial of service for all users.
- Weakness
- CWE-770
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.