PT-2026-33117 · Weblate · Weblate

Published

2026-04-15

·

Updated

2026-04-16

·

CVE-2026-33440

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.17
Description The ALLOWED ASSET DOMAINS setting only applied to the first issued requests and failed to restrict possible redirects.
Recommendations Update to version 5.17.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-33440
GHSA-5FHX-9JWJ-867M

Affected Products

Weblate