CyberRota Analysis
AI-GeneratedVikunja versions prior to 2.6.0 are vulnerable to a denial-of-service attack due to inadequate limits on archive expansion during data imports, allowing authenticated users to upload highly compressed files that can expand significantly, consuming excessive memory and disk space. This can lead to server resource exhaustion and potential crashes of the application instance. Organizations using Vikunja should prioritize updating to version 2.6.0 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausting server resources and crashing the instance.