GHSA-m469-88xx-8rx2

Suggest an improvement
Source
https://github.com/advisories/GHSA-m469-88xx-8rx2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-m469-88xx-8rx2/GHSA-m469-88xx-8rx2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m469-88xx-8rx2
Aliases
Published
2026-10-09T20:52:04Z
Modified
2026-10-09T21:00:10Z
Summary
Vikunja: CalDAV and feeds BasicAuth endpoints have no rate limit, bypassing the anti-brute-force floor on account passwords
Details

Summary

The /dav, /.well-known, and /feeds groups are registered on the root Echo instance with only BasicAuth and no rate limiter. CalDAV BasicAuth accepts the plain account password, so password guessing over /dav is unbounded and never returns 429, while /api/v1/login is throttled from the tenth attempt. The only anti-brute-force control on the instance is therefore bypassable.

Details

pkg/routes/routes.go (~lines 238-249) registers /.well-known, /dav, and /feeds with middleware.BasicAuth(...) and nothing else; registerCalDavRoutes adds no limiter. pkg/routes/caldav/auth.go (~lines 88-93) falls through to user.CheckUserCredentials with the plain account password when no CalDAV token matches. In contrast, /register, /login, etc. are wrapped by unauthRateLimit() — an unconditional 10/min/IP pre-auth floor that ignores ratelimit.enabled (default false).

TOTP-enabled accounts and bot users are correctly refused, so this targets password-only accounts.

PoC (verified at runtime against v2.5.0)

POST /api/v1/login  x25 wrong passwords  -> 429 from attempt 2 (throttled)
PROPFIND /dav/principals/{user}/  x60 wrong passwords  -> 401 x60, 429 x0
GET /feeds/notifications.atom  x30 wrong passwords  -> 401 x30, 429 x0
PROPFIND /dav/... with correct password -> 207 (proves the 401s are real auth failures)

Impact

The anti-brute-force floor guarding /login is entirely absent on /dav, /feeds, and /.well-known, giving an unbounded credential-guessing surface against account passwords. (bcrypt caps throughput to a few guesses/second, but nothing caps the number of attempts.) Reported as an authentication-control bypass, not a DoS.

Fix

Apply the unconditional pre-auth rate-limit floor to the /dav, /.well-known, and /feeds groups.

Database specific
{
    "cwe_ids": [
        "CWE-307"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-09T20:52:04Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

Go / code.vikunja.io/api

Package

Name
code.vikunja.io/api
View open source insights on deps.dev
Purl
pkg:golang/code.vikunja.io/api

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.6.0

Database specific

last_known_affected_version_range
"<= 2.5.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-m469-88xx-8rx2/GHSA-m469-88xx-8rx2.json"