PT-2026-86524 · Wger · Wger

·

CVE-2026-86255

·

Published

2026-05-13

·

Updated

2026-09-06

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions wger versions prior to 2.5
Description Authenticated users can create routines with arbitrarily long date ranges because the software fails to validate the maximum duration. By triggering the date sequence computation through routine detail endpoints, an attacker can force the server to perform thousands of iterations per request. This process exhausts worker threads, resulting in a denial of service for legitimate users.
Recommendations Update wger to version 2.5 or later.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86255
GHSA-V25J-WQCW-FVHJ

Affected Products

Wger