CVE-2026-50127
published 2026-06-10CVE-2026-50127: Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some…
PriorityP434medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.47%
38.2th percentile
Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions. This issue has been patched in version 2026.6.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | >= 5.15 < 2026.6 | 2026.6 |
| weblateorg | weblate | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Weblate SSRF: outbound URL guard misses some private ranges
ghsa·2026-07-07
CVE-2026-50127 [MEDIUM] CWE-918 Weblate SSRF: outbound URL guard misses some private ranges
Weblate SSRF: outbound URL guard misses some private ranges
### Impact
Weblate's `VCS_RESTRICT_PRIVATE` did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions.
### Patches
* https://github.com/WeblateOrg/weblate/pull/19768
### Resources
The issue was reported by @tonghuaroot via GitHub, and the same user also provided the initial patch.
VulDB
weblate up to 2026.5 server-side request forgery (GHSA-vmfc-9982-2m45 / EUVD-2026-36113)
vuldb·2026-06-10·CVSS 5.9
CVE-2026-50127 [MEDIUM] weblate up to 2026.5 server-side request forgery (GHSA-vmfc-9982-2m45 / EUVD-2026-36113)
A vulnerability marked as critical has been reported in weblate up to 2026.5. The affected element is an unknown function. This manipulation causes server-side request forgery.
This vulnerability is registered as CVE-2026-50127. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-10
Published