CVE-2026-34727
High Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the ma...
Related Vulnerabilities
- CVE-2026-6042: A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the MEDIUM
- CVE-2026-32146: Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows a MEDIUM
- CVE-2026-33456: Livestatus injection in the notification test mode in Checkmk MEDIUM
- CVE-2026-5500: wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication t HIGH
- CVE-2026-5187: Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. LOW
Related Coverage
Threat Actors