PT-2026-2288 · Weblate+3 · Weblate+3

Zee99Y

·

Published

2026-01-12

·

Updated

2026-01-27

·

CVE-2026-22250

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 1.17.0
Description The Weblate command-line client, wlc, which utilizes Weblate's REST API, had a flaw where SSL verification was bypassed for specific, manipulated URLs. This could potentially allow for man-in-the-middle attacks. The issue was addressed in version 1.17.0. The vulnerable component interacts with Weblate's REST API endpoints.
Recommendations Update to version 1.17.0 or later.

Exploit

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2026-22250
GHSA-2MMV-7RRP-G8XH
USN-7981-1

Affected Products

Linuxmint
Ubuntu
Weblate
Wlc