Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-39845

Опубликовано: 15 апр. 2026
Источник: debian

Описание

Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook add-on as a workaround.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
weblateitppackage

Связанные уязвимости

CVSS3: 4.1
nvd
4 месяца назад

Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook add-on as a workaround.

CVSS3: 4.1
github
4 месяца назад

Weblate: SSRF via the webhook add-on using unprotected fetch_url()