wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousands of times per request and exhaust worker threads, denying service to legitimate users.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 06 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousands of times per request and exhaust worker threads, denying service to legitimate users. | |
| Title | wger before 2.5 Uncontrolled Resource Consumption via date_sequence | |
| First Time appeared |
Wger
Wger wger |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:wger:wger:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wger
Wger wger |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-06T12:00:29.574Z
Reserved: 2026-09-06T11:35:19.317Z
Link: CVE-2026-86255
No data.
Status : Received
Published: 2026-09-06T12:17:16.433
Modified: 2026-09-06T12:17:16.433
Link: CVE-2026-86255
No data.
OpenCVE Enrichment
Updated: 2026-09-06T14:30:09Z
Weaknesses