Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests pointing to attacker-controlled servers advertising numerous size-compliant attachments, exhausting worker memory and causing denial of service for all users. | |
| Title | Vikunja before 2.6.0 Resource Exhaustion via Planka Migration | |
| First Time appeared |
Vikunja
Vikunja vikunja |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vikunja
Vikunja vikunja |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T16:02:52.721Z
Reserved: 2026-09-15T11:09:54.873Z
Link: CVE-2026-91970
No data.
Status : Received
Published: 2026-09-15T16:17:53.803
Modified: 2026-09-15T17:17:43.110
Link: CVE-2026-91970
No data.
OpenCVE Enrichment
No data.