CVE-2026-86255
Dashboard / Vulnerabilities / CVE-2026-86255
Summary: wger before 2.5 Uncontrolled Resource Consumption via date_sequence
Details: wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousands of times per request and exhaust worker threads, denying service to legitimate users.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86255.json, https://github.com/wger-project/wger/security/advisories/GHSA-v25j-wqcw-fvhj, https://nvd.nist.gov/vuln/detail/CVE-2026-86255, https://www.vulncheck.com/advisories/wger-before-2.5-uncontrolled-resource-consumption-via-date-sequence
Affected packages
Package
Name:
Purl:
