Uncontrolled Resource Consumption in wger by wger Project
CVE-2026-86255

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
6 September 2026

What is CVE-2026-86255?

The wger application prior to version 2.5 fails to properly validate the maximum duration of routine date ranges. This oversight allows authenticated users to create routines that can span excessively long periods. An attacker can exploit this vulnerability by triggering the date_sequence computation through routine detail endpoints, leading to the server needing to process thousands of iterations per request. As a result, this can deplete the available worker threads, effectively denying service to legitimate users and degrading overall application performance.

Affected Version(s)

wger 0 < 2.5

wger 2.5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

KadirArslan
.