CVE-2025-49134

Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. This issue has been patched in version 5.12.
Configurations

Configuration 1 (hide)

cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*

History

16 Jul 2025, 14:35

Type Values Removed Values Added
References () https://github.com/WeblateOrg/weblate/commit/020b2905e4d001cff2452574d10e6cf3621b5f62 - () https://github.com/WeblateOrg/weblate/commit/020b2905e4d001cff2452574d10e6cf3621b5f62 - Patch
References () https://github.com/WeblateOrg/weblate/pull/15102 - () https://github.com/WeblateOrg/weblate/pull/15102 - Issue Tracking
References () https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.12.1 - () https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.12.1 - Release Notes
References () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-4qqf-9m5c-w2c5 - () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-4qqf-9m5c-w2c5 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*
First Time Weblate
Weblate weblate

17 Jun 2025, 20:50

Type Values Removed Values Added
Summary
  • (es) Weblate es una herramienta de localización web. Antes de la versión 5.12, las notificaciones del registro de auditoría incluían la dirección IP completa del usuario. Esta podía obtenerse mediante servidores externos, como repetidores SMTP o filtros de spam. Este problema se ha corregido en la versión 5.12.

16 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-16 21:15

Updated : 2025-07-16 14:35


NVD link : CVE-2025-49134

Mitre link : CVE-2025-49134

CVE.ORG link : CVE-2025-49134


JSON object : View

Products Affected

weblate

  • weblate
CWE
CWE-359

Exposure of Private Personal Information to an Unauthorized Actor