Back

MEDIUM

Vikunja has an Algorithmic Complexity DoS in Repeating Task Handler

Published Apr 10, 2026

Description

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function uses an O(n) loop that advances a date by the task's RepeatAfter duration until it exceeds the current time. By creating a repeating task with a 1-second interval and a due date far in the past, an attacker triggers billions of loop iterations, consuming CPU and holding a database connection for minutes per request. This vulnerability is fixed in 2.3.0.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 10, 2026
Updated Apr 10, 2026
Reserved Apr 3, 2026
CISA Vulnrichment
Updated Apr 10, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Apr 10, 2026
Updated Apr 10, 2026
Exploited since n/a
EUVD-2026-21426 GHSA-R4FG-73RC-HHH7