GHSA-55p4-8j34-jv53

Suggest an improvement
Source
https://github.com/advisories/GHSA-55p4-8j34-jv53
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-55p4-8j34-jv53/GHSA-55p4-8j34-jv53.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-55p4-8j34-jv53
Withdrawn
2026-10-09T20:53:08Z
Published
2026-09-15T18:32:30Z
Modified
2026-10-09T21:00:05Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: Vikunja: Unbounded CSV row cardinality permits API process termination
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-pqf9-h8g4-8gmh. This link is maintained to preserve external references.

Original Description

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions of tiny records to exhaust process memory and terminate the API service.

Database specific
{
    "cwe_ids": [
        "CWE-400"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-09T20:53:08Z",
    "nvd_published_at": "2026-09-15T16:17:53Z",
    "severity": "HIGH"
}
References

Affected packages

Go / code.vikunja.io/api

Package

Name
code.vikunja.io/api
View open source insights on deps.dev
Purl
pkg:golang/code.vikunja.io/api

Affected ranges

Affected versions

2.*
2.5.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-55p4-8j34-jv53/GHSA-55p4-8j34-jv53.json"