Disclosure summary
### Summary A vulnerability exists in the authentication/session lifecycle of `wger` where **bearer-style API credentials** remain valid **after a user logs out and after a user changes their password**. An attacker who steals a victim’s **DRF authtoken** (`Authorization: Token ...`) or **JWT refresh token** can continue to access protected `/api/v2/*` endpoints until the token is manually rotated/deleted (DRF token) or naturally expires (JWT refresh). lifecycle events do not revoke these credentials: - **Logout** (`/user/logout`) only clears the Django session cookie via `django_logout()` and does not revoke API tokens. - **Password change** updates the password hash, but does not revoke: - existing DRF tokens stored in `authtoken_token` - existing JWT refresh tokens (no server-side revocation list or token versioning); refresh can continue minting new access tokens until refresh expiry. #### Vulnerable Files - `wger/wger/core/views/user.py` (logout implementation) - `wger/settings/settings_global.py` (DRF auth configuration, SimpleJWT defaults) - `wger/settings/main.py` (commonly used production defaults for JWT lifetimes) - `wger/wger/utils/api_token.py` (authtoken rotation is m
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-v3x9-6gg8-c2c9
Open original source · Updated Oct 07, 2026
wger: API credentials remain valid after logout/password change
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | wger | Not supplied |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T09:59:10-04:00
MODIFIED 2026-10-07T09:59:11-04:00
INGESTED 2026-10-08T12:05:11-04:00