# CVE-2026-91968

## Summary

- **CVE ID:** CVE-2026-91968
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-674
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 15, 2026

## Description

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and terminate the API process.

## Affected Products

- go-vikunja — vikunja (2.5.0)
- go-vikunja — vikunja (2.6.0)

## References

- [CNA](https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xxc3-xpmc-vmvr)
- [CNA](https://www.vulncheck.com/advisories/vikunja-before-2.6.0-denial-of-service-via-unbounded-filter-recursion)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.37%
- **EPSS Percentile:** 30.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._