vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can up…
Medium CVSS 6.5
Summary
vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions of tiny records to exhaust process memory and terminate the API service.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/go-vikunja/vikunja/security/advisories/GHSA-pqf9-h8g4-8gmh
- https://www.vulncheck.com/advisories/vikunja-before-2.6.0-resource-exhaustion-via-csv-migration
Timeline
- nvd_ingest NVD