HIGH
vikunja before 2.6.0 Denial of Service via unbounded filter recursion
Published Sep 15, 2026
7.1
HIGHCVSS 4.0
EPSS 0.44%
Description
vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and terminate the API process.
Affected products
-
Affected
- ≥ 2.5.0, < 2.6.0
Unaffected
- 2.6.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| GO-Vikunja | Vikunja | unaffected | Affected
Unaffected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-78644 Advisory
- https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xxc3-xpmc-vmvr exploitvendor-advisory
- https://www.vulncheck.com/advisories/vikunja-before-2.6.0-denial-of-service-via-unbounded-filter-recursion third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-78644 | Advisory | |
| https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xxc3-xpmc-vmvr | exploitvendor-advisory | |
| https://www.vulncheck.com/advisories/vikunja-before-2.6.0-denial-of-service-via-unbounded-filter-recursion | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 15, 2026
Updated Sep 15, 2026
Reserved Sep 15, 2026
Link CVE-2026-91968
CISA Vulnrichment
Updated Sep 15, 2026
Red Hat
No data
GitHub
No data