CVE-2026-35602
Medium Severity
Description
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size field from t...
Related Vulnerabilities
- CVE-2026-35195: Wasmtime has out-of-bounds write or crash when transcoding component model strings MEDIUM
- CVE-2026-39315: Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe() MEDIUM
- CVE-2026-5503: In TLSX_EchChangeSNI, the ctx->extensions branch set extensions unconditionally even when TLSX_Find MEDIUM
- CVE-2026-5724: The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor N/A
- CVE-2026-40259: SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttribut HIGH
Related Coverage
Threat Actors