CVE-2026-35602
Medium Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from t...
Related Vulnerabilities
- CVE-2026-40160: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path pas HIGH
- CVE-2026-40199: Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow MEDIUM
- CVE-2026-5507: When restoring a session from cache, a pointer from the serialized session data is used in a free op MEDIUM
- CVE-2026-40242: Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint HIGH
- CVE-2026-6007: A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknow MEDIUM
Related Coverage
Threat Actors