PT-2026-33124 · Weblate · Weblate

Published

2026-04-15

·

Updated

2026-04-16

·

CVE-2026-39845

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.17
Description The webhook add-on fails to utilize existing Server-Side Request Forgery (SSRF) protections. SSRF is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.
Recommendations Update to version 5.17. As a temporary workaround, disable the webhook add-on.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-39845
GHSA-F8HV-G549-HWG2
PYSEC-2026-156

Affected Products

Weblate