PT-2026-33121 · Weblate · Weblate

Published

2026-04-15

·

Updated

2026-04-16

·

CVE-2026-34244

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.17
Description A user with the project.edit permission, granted by the per-project Administration role, can configure machine translation service URLs to point to arbitrary internal network addresses. During the validation of this configuration, the application performs an HTTP request to the specified URL and returns up to 200 characters of the response body within an error message. This allows for Server-Side Request Forgery (SSRF), which is a flaw where a server is tricked into making requests to an unintended location, combined with a partial response read.
Recommendations Update to version 5.17. Limit available machinery services via the WEBLATE MACHINERY setting.

Fix

Information Disclosure

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-34244
GHSA-XRWR-FCW6-FMQ8

Affected Products

Weblate