GHSA-f8hv-g549-hwg2MediumCVSS 4.1
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
🔗 CVE IDs covered (1)
📋 Description
Impact
The webhook add-on did not utilize existing SSRF protection.
Patches
- https://github.com/WeblateOrg/weblate/pull/18815
Workarounds
Disabling the add-on would avoid misusing this.
References
Thanks to @Lihfdgjr for reporting this via GitHub.
🎯 Affected products1
- pip/weblate:< 5.17
🔗 References (5)
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-f8hv-g549-hwg2
- https://nvd.nist.gov/vuln/detail/CVE-2026-39845
- https://github.com/WeblateOrg/weblate/pull/18815
- https://github.com/pypa/advisory-database/tree/main/vulns/weblate/PYSEC-2026-156.yaml
- https://github.com/advisories/GHSA-f8hv-g549-hwg2