CVE-2026-91969
vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions of tiny records to exhaust process memory and terminate the API service.
- Published Sep 15, 2026
- CVSS 7.1 high
- 0.4% chance of exploitation in the next 30 days (EPSS)
- A fix is available