CVE-2026-91979
nicheAuthenticated Archive-Bomb Denial of Service in Vikunja before 2.6.0
Vikunja, an open-source self-hosted to-do/task-management application, fails to limit archive expansion during its data-import feature in all versions before 2.6.0 (CWE-400). An authenticated user can upload a highly compressed archive (a 'zip bomb') that expands to tens of gigabytes of data in memory and on disk when the server processes the import. This exhausts server resources and crashes or freezes the Vikunja instance, causing denial of service for all users of that deployment; the attacker gains no confidentiality or integrity impact. Any self-hosted or hosted Vikunja instance running a version earlier than 2.6.0 that allows authenticated users to run imports is affected. The flaw is not in the CISA KEV catalog and no public proof-of-concept is known, so exploitation is presumed limited at this time.
What to do: Upgrade to Vikunja 2.6.0 or later, which caps archive expansion during import. If immediate upgrade is not possible, restrict who can use the import feature, enforce upload size and quota limits at the reverse proxy or application level, and monitor server memory and disk usage for spikes following import activity.
| Vikunja | before 2.6.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausting server resources and crashing the instance.
- Weakness
- CWE-400
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.