MEDIUMVulnerability

CVE-2026-86255

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousands of times per request and exhaust worker threads, denying service to legitimate users.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-86255
signal_observed_at
2026-09-18T21:50:21+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
published_at
2026-09-06T12:17:16.433
last_modified
2026-09-18T18:17:18.790

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Uncontrolled Resource Consumption

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86255 — Ninja Signal Threat Intelligence | Ninja Signal