CVE-2026-91970: Go-Vikunja Vikunja
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests pointing to attacker-controlled servers advertising numerous size-compliant attachments, exhausting worker memory and causing denial of service for all users.
Affected products
- Go-Vikunja Vikunja: before 2.6.0 (fixed in 2.6.0)
Published 2026-09-15. Last modified 2026-09-16.