Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-22251

Опубликовано: 12 янв. 2026
Источник: nvd
CVSS3: 5.3
CVSS3: 5.5
EPSS Низкий

Описание

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:weblate:wlc:*:*:*:*:*:*:*:*
Версия до 1.17.0 (исключая)

EPSS

Процентиль: 1%
0.00011
Низкий

5.3 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
ubuntu
26 дней назад

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.

CVSS3: 5.3
debian
26 дней назад

wlc is a Weblate command-line client using Weblate's REST API. Prior t ...

CVSS3: 5.3
github
26 дней назад

Weblate wlc has insecure API key configuration

EPSS

Процентиль: 1%
0.00011
Низкий

5.3 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo