PT-2026-48524 · Weblateorg · Weblate
Published
2026-06-10
·
Updated
2026-06-10
·
CVE-2026-50127
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS RESTRICT PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions. This issue has been patched in version 2026.6.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Weblate