{"id":"CVE-2026-86255","aliases":["GHSA-v25j-wqcw-fvhj"],"url":"https://o3.security/vulnerability/CVE-2026-86255","summary":"wger before 2.5 Uncontrolled Resource Consumption via date_sequence","details":"wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousands of times per request and exhaust worker threads, denying service to legitimate users.","published":"2026-09-06T12:00:29.574Z","modified":"2026-09-08T03:47:11.643171935Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"wger","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86255.json"},{"type":"ADVISORY","url":"https://github.com/wger-project/wger/security/advisories/GHSA-v25j-wqcw-fvhj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86255"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/wger-before-2.5-uncontrolled-resource-consumption-via-date-sequence"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-08T03:47:11.643171935Z"}}