CVE-2026-91971: Vikunja: Unbounded image decode on avatar and project-background uploads enables decode/resize amplification
The 50-megapixel decode guard exists only on the task-attachment preview path. Avatar and project-background uploads decode uploaded images with no pixel cap. Worse, the avatar resize fixes the output height at 1024 and derives the width from the aspect ratio, so a tiny extreme-aspect-ratio PNG expands to an enormous output image — an input-side pixel cap would not catch it.
References
- github.com/advisories/GHSA-4vh2-39rq-rq8j
- github.com/go-vikunja/vikunja/pull/3688
- github.com/go-vikunja/vikunja/releases/tag/v2.6.0
- github.com/go-vikunja/vikunja/security/advisories/GHSA-4vh2-39rq-rq8j
- nvd.nist.gov/vuln/detail/CVE-2026-91971
- www.vulncheck.com/advisories/vikunja-before-2.6.0-denial-of-service-via-avatar-upload
Code Behaviors & Features
Detect and mitigate CVE-2026-91971 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →