<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T14:36:56.320390+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-290479</id>
    <title>EUVD-2026-290479</title>
    <updated>2026-10-05T14:36:56.367895+00:00</updated>
    <content>EUVD-2026-290479</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-290479"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35599</id>
    <title>fkie_cve-2026-35599</title>
    <updated>2026-10-05T14:36:56.367932+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function uses an O(n) loop that advances a date by the task's RepeatAfter duration until it exceeds the current time. By creating a repeating task with a 1-second interval and a due date far in the past, an attacker triggers billions of loop iterations, consuming CPU and holding a database connection for minutes per request. This vulnerability is fixed in 2.3.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35599"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r4fg-73rc-hhh7</id>
    <title>GHSA-r4fg-73rc-hhh7 — Vikunja has Algorithmic Complexity DoS in Repeating Task Handler</title>
    <updated>2026-10-05T14:36:56.367975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: code.vikunja.io/api</p>
<p>## Summary</p>
<p>The `addRepeatIntervalToTime` function uses an O(n) loop that advances a date by the task's `RepeatAfter` duration until it exceeds the current time. By creating a repeating task with a 1-second interval and a due date far in the past, an attacker triggers billions of loop iterations, consuming CPU and holding a database connection for minutes per request.</p>
<p>## Details</p>
<p>The vulnerable function at `pkg/models/tasks.go:1456-1464`:</p>
<p>```go
func addRepeatIntervalToTime(now, t time.Time, duration time.Duration) time.Time {
    for {
        t = t.Add(duration)
        if t.After(now) {
            break
        }
    }
    return t
}
```</p>
<p>The `RepeatAfter` field accepts any positive integer (validated as `range(0|9223372036854775807)`), and `DueDate` accepts any valid timestamp including dates far in the past. When a task with `repeat_after=1` and `due_date=1900-01-01` is marked as done, the loop runs approximately 4 billion iterations (~60+ seconds of CPU time).</p>
<p>Each request holds a goroutine and a database connection for the duration. With the default connection pool size of 100, approximately 100 concurrent requests exhaust all available connections.</p>
<p>## Proof of Concept</p>
<p>Tested on Vikunja v2.2.2.</p>
<p>```python
import requests, time</p>
<p>TARGET = "http://localhost:3456"
API = f"{TARGET}/api/v1"</p>
<p>token = requests.post(f"{API}/login",
    json={"username": "user1", "password": "User1pass!"}).json()["token"]
h = {"Authorization": f"Bearer {token}", "Content-Type": "applicatio…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r4fg-73rc-hhh7"/>
  </entry>
</feed>
