CVE-2026-34244

Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation service URLs pointing to arbitrary internal network addresses. During configuration validation, Weblate makes an HTTP request to the attacker-controlled URL and reflects up to 200 characters of the response body back to the user in an error message. This constitutes a Server-Side Request Forgery (SSRF) with partial response read. This issue has been fixed in version 5.17. If developers are unable to immediately upgrade, they can limit available machinery services via WEBLATE_MACHINERY setting.
Configurations

Configuration 1 (hide)

cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*

History

21 Apr 2026, 14:06

Type Values Removed Values Added
First Time Weblate
Weblate weblate
CPE cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*
References () https://github.com/WeblateOrg/weblate/commit/e619e9090202e4886b844c110d39308e7e882c0e - () https://github.com/WeblateOrg/weblate/commit/e619e9090202e4886b844c110d39308e7e882c0e - Patch
References () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-xrwr-fcw6-fmq8 - () https://github.com/WeblateOrg/weblate/security/advisories/GHSA-xrwr-fcw6-fmq8 - Third Party Advisory

15 Apr 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-15 19:16

Updated : 2026-04-21 14:06


NVD link : CVE-2026-34244

Mitre link : CVE-2026-34244

CVE.ORG link : CVE-2026-34244


JSON object : View

Products Affected

weblate

  • weblate
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-918

Server-Side Request Forgery (SSRF)