CyberRota Analysis
AI-GeneratedVikunja versions prior to 2.6.0 are vulnerable to denial of service attacks due to inadequate pixel decode limits on avatar and project-background upload endpoints, allowing authenticated users to upload specially crafted images that demand excessive CPU and memory resources. This can lead to service disruptions through repeated or concurrent uploads. Organizations using Vikunja should prioritize this vulnerability to mitigate potential service outages and ensure system stability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts. Attackers can upload small images with extreme aspect ratios that consume significant CPU and memory during processing, causing denial of service through repeated or concurrent uploads.