SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-91979

MEDIUM · CVSS 6.5 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Vikunja versions prior to 2.6.0 are vulnerable to a denial-of-service attack due to inadequate limits on archive expansion during data imports, allowing authenticated users to upload highly compressed files that can expand significantly, consuming excessive memory and disk space. This can lead to server resource exhaustion and potential crashes of the application instance. Organizations using Vikunja should prioritize updating to version 2.6.0 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91979
Severity
MEDIUM
CVSS
6.5
EPSS
0.34%

Original NVD Description

Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausting server resources and crashing the instance.