CVE-2026-91971 PUBLISHED

Vikunja before 2.6.0 Denial of Service via Avatar Upload

Assigner: VulnCheck
Reserved: 15.09.2026 Published: 15.09.2026 Updated: 15.09.2026

Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts. Attackers can upload small images with extreme aspect ratios that consume significant CPU and memory during processing, causing denial of service through repeated or concurrent uploads.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor go-vikunja
Product vikunja
Versions Default: unaffected
  • affected from 0 to 2.6.0 (excl.)
  • Version 2.6.0 is unaffected

Credits

  • Str1ckl4nd reporter
  • 7thParkk reporter
  • JellowBeanz26 reporter

References

Problem Types

  • Uncontrolled Resource Consumption CWE