CVE-2026-22250

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:weblate:wlc:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:19

Type Values Removed Values Added
Summary
  • (es) wlc es un cliente de línea de comandos de Weblate que utiliza la API REST de Weblate. Antes de la versión 1.17.0, la verificación SSL se omitiría para algunas URL manipuladas. Esta vulnerabilidad está corregida en la versión 1.17.0.

27 Jan 2026, 20:37

Type Values Removed Values Added
References () https://github.com/WeblateOrg/wlc/commit/a513864ec4daad00146e6d6e039559726e256fa3 - () https://github.com/WeblateOrg/wlc/commit/a513864ec4daad00146e6d6e039559726e256fa3 - Patch
References () https://github.com/WeblateOrg/wlc/pull/1097 - () https://github.com/WeblateOrg/wlc/pull/1097 - Issue Tracking
References () https://github.com/WeblateOrg/wlc/security/advisories/GHSA-2mmv-7rrp-g8xh - () https://github.com/WeblateOrg/wlc/security/advisories/GHSA-2mmv-7rrp-g8xh - Third Party Advisory
CPE cpe:2.3:a:weblate:wlc:*:*:*:*:*:*:*:*
First Time Weblate wlc
Weblate

12 Jan 2026, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-12 18:15

Updated : 2026-06-17 10:19


NVD link : CVE-2026-22250

Mitre link : CVE-2026-22250

CVE.ORG link : CVE-2026-22250


JSON object : View

Products Affected

weblate

  • wlc
CWE
CWE-295

Improper Certificate Validation