GHSA-f8hv-g549-hwg2MediumCVSS 4.1

Weblate: SSRF via the webhook add-on using unprotected fetch_url()

Published
April 16, 2026
Last Modified
June 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

The webhook add-on did not utilize existing SSRF protection.

Patches

  • https://github.com/WeblateOrg/weblate/pull/18815

Workarounds

Disabling the add-on would avoid misusing this.

References

Thanks to @Lihfdgjr for reporting this via GitHub.

🎯 Affected products1

  • pip/weblate:< 5.17

🔗 References (5)