{"id":"GHSA-m469-88xx-8rx2","summary":"Vikunja: CalDAV and feeds BasicAuth endpoints have no rate limit, bypassing the anti-brute-force floor on account passwords","details":"### Summary\nThe `/dav`, `/.well-known`, and `/feeds` groups are registered on the root Echo instance with only BasicAuth and no rate limiter. CalDAV BasicAuth accepts the plain account password, so password guessing over `/dav` is unbounded and never returns 429, while `/api/v1/login` is throttled from the tenth attempt. The only anti-brute-force control on the instance is therefore bypassable.\n\n### Details\n`pkg/routes/routes.go` (~lines 238-249) registers `/.well-known`, `/dav`, and `/feeds` with `middleware.BasicAuth(...)` and nothing else; `registerCalDavRoutes` adds no limiter. `pkg/routes/caldav/auth.go` (~lines 88-93) falls through to `user.CheckUserCredentials` with the plain account password when no CalDAV token matches. In contrast, `/register`, `/login`, etc. are wrapped by `unauthRateLimit()` — an unconditional 10/min/IP pre-auth floor that ignores `ratelimit.enabled` (default false).\n\nTOTP-enabled accounts and bot users are correctly refused, so this targets password-only accounts.\n\n### PoC (verified at runtime against v2.5.0)\n```\nPOST /api/v1/login  x25 wrong passwords  -\u003e 429 from attempt 2 (throttled)\nPROPFIND /dav/principals/{user}/  x60 wrong passwords  -\u003e 401 x60, 429 x0\nGET /feeds/notifications.atom  x30 wrong passwords  -\u003e 401 x30, 429 x0\nPROPFIND /dav/... with correct password -\u003e 207 (proves the 401s are real auth failures)\n```\n\n### Impact\nThe anti-brute-force floor guarding `/login` is entirely absent on `/dav`, `/feeds`, and `/.well-known`, giving an unbounded credential-guessing surface against account passwords. (bcrypt caps throughput to a few guesses/second, but nothing caps the number of attempts.) Reported as an authentication-control bypass, not a DoS.\n\n### Fix\nApply the unconditional pre-auth rate-limit floor to the `/dav`, `/.well-known`, and `/feeds` groups.","aliases":["CVE-2026-91973"],"modified":"2026-10-09T21:00:10.211759443Z","published":"2026-10-09T20:52:04Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-09T20:52:04Z","nvd_published_at":null,"cwe_ids":["CWE-307"]},"references":[{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-m469-88xx-8rx2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91973"},{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/pull/3688"},{"type":"PACKAGE","url":"https://github.com/go-vikunja/vikunja"},{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/releases/tag/v2.6.0"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/vikunja-before-2.6.0-authentication-bypass-via-caldav-basicauth"}],"affected":[{"package":{"name":"code.vikunja.io/api","ecosystem":"Go","purl":"pkg:golang/code.vikunja.io/api"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.6.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.5.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-m469-88xx-8rx2/GHSA-m469-88xx-8rx2.json"}}],"schema_version":"1.9.0"}