CVE-2026-86255CWE-400denial-of-service

CVE-2026-86255

Medium · published September 6, 2026

CVSS v3.1
6.5
EPSS
In the wild
Unconfirmed
What it is

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousands of times per request and exhaust worker threads, denying service to legitimate users.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
7.1 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
Not scored
Weakness
CWE-400 · Uncontrolled Resource Consumption
Published
2026-09-06T16:17Z
References (2)
Timeline
  • 06 SEP 12:00Z
    wger before 2.5 Uncontrolled Resource Consumption via date_sequence
    cvelistv5