highVulnerability

CVE-2026-91979

### Summary Vikunja lets you export your data as a zip and import it back. The import doesn't limit how large the archive expands to, how many files it contains, or how much storage one user can consume, and it appears to hold the whole archive in memory while processing it. Because the archive is compressed, a ~20 MB upload made of highly compressible content expands to tens of gigabytes once imported. A single crafted upload is enough to exhaust the server's memory or fill its disk and knock the whole instance offline. It can be repeated or run in parallel, since nothing stops a user from starting several imports at once. ### Details The import accepts an archive in the same layout the built-in export produces: a manifest describing projects and tasks, plus the attachment files those tasks reference. Each individual file inside the archive is size-checked, but there's no ceiling on the total uncompressed size or on the number of files, and there's no per-user storage quota anywhere. On top of that, the server seems to buffer every attachment in memory before writing it out, so the peak memory cost is the sum of all decompressed files at once, not one at a time. Compression is the key factor: a file full of a repeating byte (e.g. zeroes) shrinks by roughly a thousand to one. So an archive that fits under the upload size limit (around 20 MB) can describe on the order of a thousand ~20 MB attachments, which the server then expands to tens of gigabytes in RAM and writes to disk. When memory runs out the process is killed; when the disk fills, the instance (and anything else on that host) stops working. Nothing serialises imports, so a user can also fire several in parallel to reach the limit faster. The fix is to cap the total uncompressed size and the file count per archive, stream each file to disk instead of buffering them all in memory, enforce a per-user storage quota, and refuse a new import while one is already running for that user. ### PoC The attacker n

Properties

ghsa_id
GHSA-w7jp-mf2v-8342
summary
Vikunja: Denial of service via decompression bomb in the data import
severity
high
last_source
GitHub Advisory Database
cve_id
CVE-2026-91979
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
false
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T20:52:52Z
source_url
https://github.com/advisories/GHSA-w7jp-mf2v-8342
ghsa_updated
2026-10-09T20:52:53Z

Related Entities (6)

VULNERABLE_TO (1)

←[Software]go/code.vikunja.io/api

AFFECTS (1)

→[Software]go/code.vikunja.io/api

HAS_WEAKNESS (3)

→[Weakness]Allocation of Resources Without Limits or Throttling
→[Weakness]Improper Handling of Highly Compressed Data (Data Amplification)
→[Weakness]Uncontrolled Resource Consumption

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-91979 — Ninja Signal Threat Intelligence | Ninja Signal