Junglewise Threat Intelligence

CVE-2026-35602: Vikunja file size limit bypass in import endpoint

CVE-2026-35602 · Severity: medium · CVSS 5.4 · Published 2026-04-10

Technologies: code.vikunja.io/api (Go), Vikunja. Vendors: Go, Vikunja.

Executive brief

Vikunja, an open-source to-do list application, contains a vulnerability in its file import feature that allows users to bypass storage limits. By providing a specially crafted import file, an authenticated user can upload much larger files than the administrator has permitted. This can be used to intentionally exhaust the server's disk space, potentially leading to a complete service outage for all users.

Technical details

The Vikunja file import endpoint fails to validate the actual size of decompressed files against configured limits. Instead of calculating the real content length, the application relies on an attacker-controlled 'Size' field within the 'data.json' metadata file inside the uploaded ZIP archive. By setting this field to 0, the size enforcement check in 'pkg/files/files.go' is bypassed. An authenticated attacker can use high compression ratios (e.g., zero-filled buffers) to upload small archives that expand into gigabytes of data on the server. This vulnerability is tracked as CVE-2026-35602 and is fixed in version 2.3.0.

Affected products

  • Vikunja Vikunja <= 2.2.2

Timeline

  • 2026-04-09: disclosed
  • 2026-04-09: patched: Fixed in version 2.3.0
  • 2026-04-10: advisory

References

Related threats