Get real-time updates on Telegram
P5Verified
CVE-2026-91979: code.vikunja.io/api <= 2.5.0
CVE-2026-91979 affects code.vikunja.io/api. EPSS 0.00436 (percentile 0.35879), scored 2026-10-09. Affected range: <= 2.5.0. Fixed version: 2.6.0.
Affected technology
code.vikunja.io/api · <= 2.5.0
Vendor not specified by the source
Component: Not specified by the source
What an attacker can do
Or how much storage one user can consume, and it appears to hold the whole archive in memory while processing it.
- Product
- code.vikunja.io/api
- CCR priority
- 0.1 /100 (P5)
- EPSS
- 0.00436 · percentile 0.35879 · 2026-10-09
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-09 22:06:25.045838+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-91979.html