CVE-2026-35601 | go-vikunja up to 2.2.x iCalendar VTODO Entry crlf injection (GHSA-2g7h-7rqr-9p4r)
A vulnerability marked as problematic has been reported in go-vikunja vikunja up to 2.2.x. This impacts an unknown function of the component iCalendar VTODO Entry Handler. Performing a manipulation results in crlf injection.
This vulnerability is identified as CVE-2026-35601. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.