{"id":"GHSA-6rvj-qwjf-3m4q","summary":"Vikunja: Every /api/v2 pre-auth endpoint is unthrottled on a stock install while its /api/v1 twin is rate limited","details":"### Summary\n`registerAPIRoutesV2` never applies the unconditional pre-auth rate-limit floor (`unauthRateLimit()`) to the v2 public routes — it passes that limiter only to `/api/v2/ws` — and otherwise relies on `setupRateLimit`, which registers nothing when `ratelimit.enabled` is false (the default). So on a stock install every v2 pre-auth endpoint (login, register, password-reset token, oauth token) is unthrottled, while its v1 twin is throttled.\n\n### Details\n`unauthRateLimit()` -\u003e `perMinuteIPRateLimit(\"noauth\", RateLimitNoAuthRoutesLimit)` (`pkg/routes/rate_limit.go`, ~lines 100-118) is an unconditional per-IP floor (default 10/60s) that deliberately ignores `RateLimitEnabled`, which is why v1's pre-auth routes are throttled even with the global limiter off. v1 applies it: `ur := a.Group(\"\"); ur.Use(unauthRateLimit())` (`pkg/routes/routes.go` ~line 459). `registerAPIRoutesV2` (~lines 405-431) passes the `unauthRateLimit()` instance only to `/api/v2/ws`; its auth routes get only `setupRateLimit(a, ...)`, which is config-gated and registers nothing by default.\n\n### PoC (verified at runtime against v2.5.0)\n```\nPOST /api/v1/login              x25 -\u003e 429 from attempt 5\nPOST /api/v2/login              x25 -\u003e 403 x25, 429 x0\nPOST /api/v1/user/password/token     -\u003e 429 (throttled)\nPOST /api/v2/user/password/token x20 -\u003e 404 x20, 429 x0\n```\nRequest bodies are byte-identical across versions (shared `user.Login` / `user.PasswordTokenRequest`). Both v2 endpoints reach their handlers (403/404, not route-404), so the comparison is valid.\n\n### Impact\nThe pre-auth rate-limit floor — the instance's only default anti-brute-force / anti-abuse control — is absent on all v2 public endpoints. Enables unbounded credential guessing, account-enumeration probing, and password-reset flooding on a default install. Reported as an authentication-control bypass, not a DoS.\n\n### Fix\nApply `unauthRateLimit()` to the v2 public route group, matching v1.","aliases":["CVE-2026-91972"],"modified":"2026-10-09T21:00:09.102808157Z","published":"2026-10-09T20:51:05Z","database_specific":{"cwe_ids":["CWE-307"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-09T20:51:05Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-6rvj-qwjf-3m4q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91972"},{"type":"PACKAGE","url":"https://github.com/go-vikunja/vikunja"},{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/releases/tag/v2.6.0"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/vikunja-before-2.6.0-authentication-bypass-via-unthrottled-api"}],"affected":[{"package":{"name":"code.vikunja.io/api","ecosystem":"Go","purl":"pkg:golang/code.vikunja.io/api"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.6.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.5.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6rvj-qwjf-3m4q/GHSA-6rvj-qwjf-3m4q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}