CVE-2026-35597
Medium Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanism is non-functional due to a database t...
Related Vulnerabilities
- CVE-2026-40177: ajenti.plugin.core has password bypass when 2FA is activated CRITICAL
- CVE-2026-35663: OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators HIGH
- CVE-2026-40188: goshs is Missing Write Protection for Parametric Data Values HIGH
- CVE-2026-35041: fast-jwt has a ReDoS when using RegExp in allowed* leading to CPU exhaustion during token verificati MEDIUM
- CVE-2026-40190: LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in I MEDIUM
Related Coverage
Threat Actors