CVE-2026-39845
published 2026-04-15CVE-2026-39845: Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in…
PriorityP418medium4.1CVSS 3.1
AVNACLPRHUINSCCLINAN
EPSS
0.27%
20.1th percentile
Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook add-on as a workaround.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | < 5.17 | 5.17 |
| weblate | weblate | >= 0 < 5.17 | 5.17 |
| weblateorg | weblate | < 5.17 | 5.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
weblate up to 5.16 Webhook Add-on server-side request forgery (GHSA-f8hv-g549-hwg2)
vuldb·2026-04-16·CVSS 4.1
CVE-2026-39845 [MEDIUM] weblate up to 5.16 Webhook Add-on server-side request forgery (GHSA-f8hv-g549-hwg2)
A vulnerability classified as critical was found in weblate up to 5.16. This issue affects some unknown processing of the component Webhook Add-on. Such manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-39845. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
ghsa·2026-04-16
CVE-2026-39845 [MEDIUM] CWE-918 Weblate: SSRF via the webhook add-on using unprotected fetch_url()
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
### Impact
The webhook add-on did not utilize existing SSRF protection.
### Patches
* https://github.com/WeblateOrg/weblate/pull/18815
### Workarounds
Disabling the add-on would avoid misusing this.
### References
Thanks to @Lihfdgjr for reporting this via GitHub.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-15
Published