GHSA-6rvj-qwjf-3m4q

Suggest an improvement
Source
https://github.com/advisories/GHSA-6rvj-qwjf-3m4q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6rvj-qwjf-3m4q/GHSA-6rvj-qwjf-3m4q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6rvj-qwjf-3m4q
Aliases
Published
2026-10-09T20:51:05Z
Modified
2026-10-09T21:00:09Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Vikunja: Every /api/v2 pre-auth endpoint is unthrottled on a stock install while its /api/v1 twin is rate limited
Details

Summary

registerAPIRoutesV2 never applies the unconditional pre-auth rate-limit floor (unauthRateLimit()) to the v2 public routes — it passes that limiter only to /api/v2/ws — and otherwise relies on setupRateLimit, which registers nothing when ratelimit.enabled is false (the default). So on a stock install every v2 pre-auth endpoint (login, register, password-reset token, oauth token) is unthrottled, while its v1 twin is throttled.

Details

unauthRateLimit() -> perMinuteIPRateLimit("noauth", RateLimitNoAuthRoutesLimit) (pkg/routes/rate_limit.go, ~lines 100-118) is an unconditional per-IP floor (default 10/60s) that deliberately ignores RateLimitEnabled, which is why v1's pre-auth routes are throttled even with the global limiter off. v1 applies it: ur := a.Group(""); ur.Use(unauthRateLimit()) (pkg/routes/routes.go ~line 459). registerAPIRoutesV2 (~lines 405-431) passes the unauthRateLimit() instance only to /api/v2/ws; its auth routes get only setupRateLimit(a, ...), which is config-gated and registers nothing by default.

PoC (verified at runtime against v2.5.0)

POST /api/v1/login              x25 -> 429 from attempt 5
POST /api/v2/login              x25 -> 403 x25, 429 x0
POST /api/v1/user/password/token     -> 429 (throttled)
POST /api/v2/user/password/token x20 -> 404 x20, 429 x0

Request bodies are byte-identical across versions (shared user.Login / user.PasswordTokenRequest). Both v2 endpoints reach their handlers (403/404, not route-404), so the comparison is valid.

Impact

The pre-auth rate-limit floor — the instance's only default anti-brute-force / anti-abuse control — is absent on all v2 public endpoints. Enables unbounded credential guessing, account-enumeration probing, and password-reset flooding on a default install. Reported as an authentication-control bypass, not a DoS.

Fix

Apply unauthRateLimit() to the v2 public route group, matching v1.

Database specific
{
    "cwe_ids": [
        "CWE-307"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-09T20:51:05Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

Go / code.vikunja.io/api

Package

Name
code.vikunja.io/api
View open source insights on deps.dev
Purl
pkg:golang/code.vikunja.io/api

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.6.0

Database specific

last_known_affected_version_range
"<= 2.5.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6rvj-qwjf-3m4q/GHSA-6rvj-qwjf-3m4q.json"