Executive brief
wger is a workout management and fitness tracking application. Authenticated users can exploit insufficient validation of routine date ranges to create routines spanning 100+ years, then trigger expensive server-side computations that force the application to process tens of thousands of entries per request. This allows attackers to exhaust server resources and deny legitimate users access to the service.
Technical details
The vulnerability stems from missing maximum duration validation on routine date ranges in the Routine model (wger/manager/models/routine.py). The date_sequence property uses an unbounded while loop that iterates once per day between start and end dates with no upper limit, performing O(slots × entries × configs) work per iteration. An authenticated attacker can create a routine spanning 100 years (36,525+ iterations) and trigger the computation via five API endpoints (/api/v2/routine/{id}/date-sequence-display/, -gym/, /structure/, /logs/, /stats/), each single request consuming multiple seconds of CPU and returning tens of thousands of entries. Repeated requests exhaust worker threads and deny service to other users. The issue is patched in version 2.6 by adding maximum duration validation.
Affected products
- wger project wger before 2.5
Timeline
- 2026-05-08: disclosed
- 2026-09-06: published
- 2026: patched: Fixed in version 2.6