CVE-2026-91970: Go-Vikunja Vikunja

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests pointing to attacker-controlled servers advertising numerous size-compliant attachments, exhausting worker memory and causing denial of service for all users.

Affected products

Published 2026-09-15. Last modified 2026-09-16.