Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and terminate the API process. | |
| Title | vikunja before 2.6.0 Denial of Service via unbounded filter recursion | |
| First Time appeared |
Vikunja
Vikunja vikunja |
|
| Weaknesses | CWE-674 | |
| CPEs | cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vikunja
Vikunja vikunja |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:56:07.929Z
Reserved: 2026-09-15T11:08:44.670Z
Link: CVE-2026-91968
Updated: 2026-09-15T15:55:54.060Z
Status : Received
Published: 2026-09-15T16:17:53.093
Modified: 2026-09-15T16:17:53.093
Link: CVE-2026-91968
No data.
OpenCVE Enrichment
No data.
-
CWE-674
Uncontrolled Recursion