CVE-2026-33440
published 2026-04-15CVE-2026-33440: Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't…
PriorityP426medium5CVSS 3.1
AVNACLPRLUINSCCLINAN
EPSS
0.24%
15.4th percentile
Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. This issue has been fixed in version 5.17.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | < 5.17 | 5.17 |
| weblate | weblate | >= 0 < 5.17 | 5.17 |
| weblateorg | weblate | < 5.17 | 5.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
ghsa·2026-04-16
CVE-2026-33440 [MEDIUM] CWE-918 Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
### Impact
The ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects.
### Patches
* https://github.com/WeblateOrg/weblate/pull/18550
### References
This issue was reported by @spbavarva via GitHub.
VulDB
weblate up to 5.16 Setting ALLOWED_ASSET_DOMAINS server-side request forgery (GHSA-5fhx-9jwj-867m)
vuldb·2026-04-16·CVSS 5.0
CVE-2026-33440 [MEDIUM] weblate up to 5.16 Setting ALLOWED_ASSET_DOMAINS server-side request forgery (GHSA-5fhx-9jwj-867m)
A vulnerability categorized as critical has been discovered in weblate up to 5.16. This impacts an unknown function of the component Setting Handler. Such manipulation of the argument ALLOWED_ASSET_DOMAINS leads to server-side request forgery.
This vulnerability is documented as CVE-2026-33440. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-15
Published