Security: go-vikunja/vikunja
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Unbounded nested task-filter recursion permits API process terminationGHSA-xxc3-xpmc-vmvr published
Aug 31, 2026 by kolaenteHigh -
Unbounded CSV row cardinality permits API process terminationGHSA-pqf9-h8g4-8gmh published
Aug 31, 2026 by kolaenteHigh -
Planka migration retains an unbounded aggregate of attacker-served attachments and can OOM the APIGHSA-wq92-8x3r-fm38 published
Aug 31, 2026 by kolaenteHigh -
Unbounded image decode on avatar and project-background uploads enables decode/resize amplificationGHSA-4vh2-39rq-rq8j published
Aug 31, 2026 by kolaenteModerate -
Every /api/v2 pre-auth endpoint is unthrottled on a stock install while its /api/v1 twin is rate limitedGHSA-6rvj-qwjf-3m4q published
Aug 31, 2026 by kolaenteModerate -
CalDAV and feeds BasicAuth endpoints have no rate limit, bypassing the anti-brute-force floor on account passwordsGHSA-m469-88xx-8rx2 published
Aug 31, 2026 by kolaenteModerate -
Assignee email addresses disclosed to read-only project members via the task assignees endpointGHSA-8wvg-r2j4-3737 published
Aug 31, 2026 by kolaenteLow -
Favorited tasks remain readable after project access is revoked, including content written post-revocationGHSA-jp29-jrxc-92vf published
Aug 31, 2026 by kolaenteModerate -
CalDAV relation creation bypasses TaskRelation.CanCreate, allowing an unauthorized write into any task by known UIDGHSA-g38j-7v97-x298 published
Aug 31, 2026 by kolaenteModerate -
Task relation deletion does not check read access to the other task, allowing cross-project relation removalGHSA-w2ch-4xgr-22ww published
Aug 31, 2026 by kolaenteLow
Learn more about advisories related to go-vikunja/vikunja in the GitHub Advisory Database