Security
Loading…

CVE-2026-86255

MEDIUMCVSS 6.5
Description

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousands of times per request and exhaust worker threads, denying service to legitimate users.

Timeline
Published:September 6th, 2026 12:17 PM
Last modified:September 6th, 2026 12:17 PM
CVSS Scoring

CVSS v3: 6.5 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute