This advisory has been withdrawn because it is a duplicate of GHSA-pqf9-h8g4-8gmh. This link is maintained to preserve external references.
vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions of tiny records to exhaust process memory and terminate the API service.
{
"cwe_ids": [
"CWE-400"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-09T20:53:08Z",
"nvd_published_at": "2026-09-15T16:17:53Z",
"severity": "HIGH"
}