Uncontrolled Resource Consumption in wger by wger Project
CVE-2026-86255
7.1HIGH
What is CVE-2026-86255?
The wger application prior to version 2.5 fails to properly validate the maximum duration of routine date ranges. This oversight allows authenticated users to create routines that can span excessively long periods. An attacker can exploit this vulnerability by triggering the date_sequence computation through routine detail endpoints, leading to the server needing to process thousands of iterations per request. As a result, this can deplete the available worker threads, effectively denying service to legitimate users and degrading overall application performance.
Affected Version(s)
wger 0 < 2.5
wger 2.5
