CVE-2026-35598
Medium Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesByList methods fetch tasks by UID from t...
Related Vulnerabilities
- CVE-2026-40162: Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability wa HIGH
- CVE-2026-35594: Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrad MEDIUM
- CVE-2026-5778: Integer underflow in wolfSSL packet sniffer LOW
- CVE-2026-40070: bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and is MEDIUM
- CVE-2026-35651: OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerabilit MEDIUM
Related Coverage
Threat Actors