CVE-2026-29794 | vikunja up to 2.1.x Header X-Forwarded-For reliance on untrusted inputs in a security decision (GHSA-m547-hp4w-j6jx / EUVD-2026-13706)
A vulnerability, which was classified as problematic, has been found in vikunja up to 2.1.x. Affected is an unknown function of the component Header Handler. This manipulation of the argument X-Forwarded-For causes reliance on untrusted inputs in a security decision.
This vulnerability is tracked as CVE-2026-29794. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.