{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3avikunjavikunja/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-91972"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Vikunja (\u003c 2.6.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Vikunja"],"content_html":"\u003cp\u003eVikunja versions prior to 2.6.0 contain a critical vulnerability in the handling of public API requests. The platform fails to apply rate limiting or throttling mechanisms to key /api/v2 authentication endpoints, including those responsible for user login, registration, password resets, and OAuth token exchanges. This architectural oversight allows remote, unauthenticated attackers to perform unbounded high-volume requests against these services. The absence of defensive controls such as IP-based throttling or request rate limiting facilitates automated brute-force attacks, large-scale account enumeration, and denial-of-service scenarios via password-reset flooding. Given the exposure of these endpoints to the public internet, defenders should prioritize upgrading to version 2.6.0 or implementing external rate-limiting controls at the web application firewall (WAF) or reverse proxy level to mitigate potential exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to user account integrity and system availability. Success in exploiting this flaw enables attackers to compromise user accounts through credential stuffing, map user existence within the application through account enumeration, and disrupt user access by flooding the password-reset infrastructure. Organizations hosting Vikunja are susceptible to automated malicious traffic that can bypass basic security protections, potentially leading to widespread account takeovers.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of Vikunja to version 2.6.0 or later immediately to apply the required rate-limiting patches.\u003c/li\u003e\n\u003cli\u003eDeploy WAF rules or reverse proxy rate-limiting configurations for the /api/v2 endpoint path to block high-frequency requests originating from single IP addresses or identified automated agents.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for anomalous spikes in POST requests to /api/v2/login, /api/v2/register, and /api/v2/password-reset.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-15T17:44:24Z","date_published":"2026-09-15T17:44:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-vikunja-rate-limiting/","summary":"Vikunja versions before 2.6.0 lack rate limiting on public /api/v2 authentication endpoints, enabling credential stuffing, account enumeration, and password-reset flooding.","title":"Unauthenticated Rate Limiting Vulnerability in Vikunja Authentication Endpoints","url":"https://feed.craftedsignal.io/briefs/2026-09-vikunja-rate-limiting/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}