Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f8hv-g549-hwg2

Опубликовано: 16 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.1

Описание

Weblate: SSRF via the webhook add-on using unprotected fetch_url()

Impact

The webhook add-on did not utilize existing SSRF protection.

Patches

Workarounds

Disabling the add-on would avoid misusing this.

References

Thanks to @Lihfdgjr for reporting this via GitHub.

Пакеты

Наименование

Weblate

pip
Затронутые версииВерсия исправления

< 5.17

5.17

EPSS

Процентиль: 20%
0.00275
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.1
nvd
4 месяца назад

Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook add-on as a workaround.

CVSS3: 4.1
debian
4 месяца назад

Weblate is a web based localization tool. In versions prior to 5.17, t ...

EPSS

Процентиль: 20%
0.00275
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-918