GHSA-2p9g-x3cv-5hh4MediumCVSS 4.3
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
🔗 CVE IDs covered (1)
📋 Description
Impact
The several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404.
Patches
- https://github.com/WeblateOrg/weblate/pull/19971
References
Thanks to Yaohui Wang for reporting this via GitHub.
🎯 Affected products1
- pip/weblate:< 2026.7
🔗 References (6)
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-2p9g-x3cv-5hh4
- https://nvd.nist.gov/vuln/detail/CVE-2026-55227
- https://github.com/WeblateOrg/weblate/pull/19971
- https://github.com/WeblateOrg/weblate/commit/836bc082803d49d02f2831ec8339268eb66bcdae
- https://github.com/WeblateOrg/weblate/releases/tag/weblate-2026.7
- https://github.com/advisories/GHSA-2p9g-x3cv-5hh4