<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 03:09:08 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-291184</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291184</link>
      <description>EUVD-2026-291184</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291184</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35602</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35602</link>
      <description>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from the JSON metadata inside the import zip instead of the actual decompressed file content length for the file size enforcement check. By setting Size to 0 in the JSON while including large compressed file entries in the zip, an attacker bypasses the configured maximum file size limit. This vulnerability is fixed in 2.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from the JSON metadata inside the import zip instead of the actual decompressed file content length for the file size enforcement check. By setting Size to 0 in the JSON while including large compressed file entries in the zip, an attacker bypasses the configured maximum file size limit. This vulnerability is fixed in 2.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35602</guid>
    </item>
    <item>
      <title>GHSA-qh78-rvg3-cv54 — Vikunja has File Size Limit Bypass via Vikunja Import</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qh78-rvg3-cv54</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The Vikunja file import endpoint uses the attacker-controlled `Size` field from the JSON metadata inside the import zip instead of the actual decompressed file content length for the file size enforcement check. By setting `Size` to 0 in the JSON while including large compressed file entries in the zip, an attacker bypasses the configured maximum file size limit.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;During import, the JSON metadata from `data.json` inside the zip archive is deserialized into project structures. File content is read independently from the zip entries. When creating attachments, the code at `pkg/modules/migration/create_from_structure.go:406` passes the attacker-controlled `File.Size` from the JSON:&lt;/p&gt;
&lt;p&gt;```go
err = a.NewAttachment(s, bytes.NewReader(a.File.FileContent), a.File.Name, a.File.Size, user)
```&lt;/p&gt;
&lt;p&gt;The file size enforcement check at `pkg/files/files.go:118` then evaluates this attacker-controlled value:&lt;/p&gt;
&lt;p&gt;```go
if realsize &amp;gt; config.GetMaxFileSizeInMBytes()*uint64(datasize.MB) &amp;amp;&amp;amp; checkFileSizeLimit {
```&lt;/p&gt;
&lt;p&gt;With `Size` set to 0 in the JSON, the comparison `0 &amp;gt; 20MB` evaluates to false and the check passes. The actual file content (from the zip entry) can be up to 500MB per entry (the `readZipEntry` limit). Highly compressible content like zero-filled buffers achieves extreme compression ratios, allowing a small zip upload to store gigabytes of data.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;Tested on Vikunja v2.2.2 with default `max_file_size: 20MB`.&lt;/p&gt;
&lt;p&gt;```python
import zipfile, io, json, req…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: code.vikunja.io/api&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The Vikunja file import endpoint uses the attacker-controlled `Size` field from the JSON metadata inside the import zip instead of the actual decompressed file content length for the file size enforcement check. By setting `Size` to 0 in the JSON while including large compressed file entries in the zip, an attacker bypasses the configured maximum file size limit.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;During import, the JSON metadata from `data.json` inside the zip archive is deserialized into project structures. File content is read independently from the zip entries. When creating attachments, the code at `pkg/modules/migration/create_from_structure.go:406` passes the attacker-controlled `File.Size` from the JSON:&lt;/p&gt;
&lt;p&gt;```go
err = a.NewAttachment(s, bytes.NewReader(a.File.FileContent), a.File.Name, a.File.Size, user)
```&lt;/p&gt;
&lt;p&gt;The file size enforcement check at `pkg/files/files.go:118` then evaluates this attacker-controlled value:&lt;/p&gt;
&lt;p&gt;```go
if realsize &amp;gt; config.GetMaxFileSizeInMBytes()*uint64(datasize.MB) &amp;amp;&amp;amp; checkFileSizeLimit {
```&lt;/p&gt;
&lt;p&gt;With `Size` set to 0 in the JSON, the comparison `0 &amp;gt; 20MB` evaluates to false and the check passes. The actual file content (from the zip entry) can be up to 500MB per entry (the `readZipEntry` limit). Highly compressible content like zero-filled buffers achieves extreme compression ratios, allowing a small zip upload to store gigabytes of data.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;Tested on Vikunja v2.2.2 with default `max_file_size: 20MB`.&lt;/p&gt;
&lt;p&gt;```python
import zipfile, io, json, req…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qh78-rvg3-cv54</guid>
    </item>
  </channel>
</rss>
