Vikunja Unbounded Image Decoding Resource Exhaustion
Vikunja versions up to 2.5.0 allow denial-of-service attacks by processing maliciously crafted high-aspect-ratio images in avatar and project-background upload endpoints that lack input validation.
CVE search metadata
CVE search record: CVE-2026-91971. Severity: medium. CVSS: 6.5. EPSS: 0.44%. KEV: no. Brief: Vikunja Unbounded Image Decoding Resource Exhaustion. Brief link: https://feed.craftedsignal.io/briefs/2026-10-vikunja-dos/
Vikunja versions up to 2.5.0 contain a critical vulnerability in the image processing logic for user avatars and project backgrounds. While the TaskAttachment preview functionality includes a 50-megapixel decode guard, the avatar and project-background upload endpoints lack equivalent input validation. An attacker can upload intentionally malformed, extreme-aspect-ratio PNG images that are computationally inexpensive to host but trigger resource exhaustion upon server-side resizing.
The flaw is amplified by the use of imaging.Resize with a fixed output height of 1024 pixels. By manipulating the input aspect ratio, an attacker can force the server to allocate massive amounts of memory and CPU cycles to render an output image with dimensions exceeding 2 billion pixels. This vulnerability (CVE-2026-91971) enables a denial-of-service condition where a few-hundred-byte file can cause significant server latency or instability via repeated or concurrent upload requests.
Attack Chain
- Attacker identifies the target instance of Vikunja running version 2.5.0 or earlier.
- Attacker crafts a small PNG file with extreme dimensions (e.g., 20000x10 pixels).
- Attacker sends a PUT request to the
/api/v1/user/settings/avatar/uploadendpoint containing the crafted image. - The application receives the request and initializes the
imaging.Resizemodule without an input-side pixel dimension check. - The server attempts to resize the image to a fixed height of 1024 pixels while maintaining the extreme aspect ratio.
- The
imaginglibrary attempts to allocate memory to process the resulting multi-gigapixel output image. - Server CPU and memory consumption spike as the image processing thread handles the excessive pixel data.
- Repeating this request causes resource exhaustion, resulting in service denial for legitimate users.
Impact
Successful exploitation results in denial of service (DoS) for the Vikunja instance. The impact is significant for organizations hosting Vikunja as a centralized task management tool, as it renders the application unresponsive or inaccessible. A single attacker can trigger this state using minimal network bandwidth and file storage, making the attack highly efficient and difficult to distinguish from legitimate user activity without specialized request-