CVE-2026-35602
Medium Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from t...
Related Vulnerabilities
- CVE-2026-35659: OpenClaw before 2026.3.22 contains a service discovery vulnerability where TXT metadata from Bonjour MEDIUM
- CVE-2026-4149: Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerabil CRITICAL
- CVE-2026-34486: Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-2914 HIGH
- CVE-2026-5392: Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the hea LOW
- CVE-2026-1502: CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. MEDIUM
Related Coverage
Threat Actors