Back

HIGH

vikunja before 2.6.0 Denial of Service via unbounded filter recursion

Published Sep 15, 2026

Description

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and terminate the API process.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Sep 15, 2026
Updated Sep 15, 2026
Reserved Sep 15, 2026

CISA Vulnrichment

Updated Sep 15, 2026

NVD

Status Deferred
Modified Sep 16, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Sep 15, 2026
Updated Sep 15, 2026

GitHub

No data