CVE-2026-91970
Received Received - Intake

Resource Exhaustion in Vikunja Planka Migrator

Vulnerability report for CVE-2026-91970, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulnCheck

Description

Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests pointing to attacker-controlled servers advertising numerous size-compliant attachments, exhausting worker memory and causing denial of service for all users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vikunja vikunja to 2.6.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-91970 is a resource exhaustion vulnerability in Vikunja versions before 2.6.0. It affects the Planka migrator component where the system fails to enforce memory limits during migration jobs. Authenticated attackers can exploit this by submitting migration requests to malicious servers hosting large compliant attachments. This causes the worker process to consume excessive memory, leading to a denial-of-service condition affecting all users.

Detection Guidance

Monitor Vikunja worker processes for excessive memory usage during migration jobs. Check for high memory consumption by the Vikunja service when migration tasks are active. Look for processes named 'vikunja' or related to Planka migration consuming abnormally high memory.

Impact Analysis

This vulnerability can cause a denial-of-service (DoS) for all users by exhausting server memory. Attackers with valid accounts can trigger the issue by initiating migrations to malicious servers, leading to system crashes or slowdowns. The impact includes service disruption, potential data loss, and degraded performance for all users.

Mitigation Strategies

Upgrade Vikunja to version 2.6.0 or later immediately. Disable the Planka migration feature if not in use. Restrict user permissions to prevent unauthorized migration requests. Monitor network traffic for suspicious migration requests to malicious servers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91970. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart