PT-2026-33121 · Weblate · Weblate
Published
2026-04-15
·
Updated
2026-04-16
·
CVE-2026-34244
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Weblate versions prior to 5.17
Description
A user with the
project.edit permission, granted by the per-project Administration role, can configure machine translation service URLs to point to arbitrary internal network addresses. During the validation of this configuration, the application performs an HTTP request to the specified URL and returns up to 200 characters of the response body within an error message. This allows for Server-Side Request Forgery (SSRF), which is a flaw where a server is tricked into making requests to an unintended location, combined with a partial response read.Recommendations
Update to version 5.17.
Limit available machinery services via the
WEBLATE MACHINERY setting.Fix
Information Disclosure
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Weblate