CVE-2026-86255

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousands of times per request and exhaust worker threads, denying service to legitimate users.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-06 12:17

Updated : 2026-09-08 19:59


NVD link : CVE-2026-86255

Mitre link : CVE-2026-86255

CVE.ORG link : CVE-2026-86255


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption