CVE-2026-91968 MEDIUM

CVE-2026-91968: vikunja before 2.6.0 Denial of Service via unbounded filter recursion

Vendor Go-Vikunja
Product vikunja
Weakness CWE-674
Published September 15, 2026
Last update September 15, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and terminate the API process.

Key dates

02Disclosure timeline

September 15, 2026 CVE published
September 15, 2026 Record updated