CVE-2026-91968: vikunja before 2.6.0 Denial of Service via unbounded filter recursion

Published Sep 15, 2026
·
Updated

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and terminate the API process.

Affected Software

1 affected component
Vikunja<2.6.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade vikunja to a version that resolves this vulnerability.

    Fixed in 2.6.0
  2. Compensating control

    Apply rate limiting / request throttling and restrict access to the task-filter endpoint to reduce the impact of deeply nested filter expressions until the service is upgraded to 2.6.0.

Event History

Sep 15, 2026
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated attacker who can send requests to the task-filter endpoint can exploit it. No user interaction is required.

2

What input triggers the denial of service?

The attacker supplies a filter query parameter containing thousands of deeply nested parentheses. The endpoint processes these expressions without a recursion-depth limit, exhausting memory and terminating the API process.

3

Are deployments running Vikunja 2.6.0 affected?

No. The affected versions are Vikunja releases before 2.6.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203