Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-22251

Опубликовано: 12 янв. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.3

Описание

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.

РелизСтатусПримечание
devel

needed

esm-apps/bionic

released

0.8-1ubuntu0.1~esm1
esm-apps/focal

released

1.2-1ubuntu0.20.04.1~esm1
esm-apps/jammy

released

1.2-1ubuntu0.22.04.1~esm1
esm-apps/noble

released

1.13-2ubuntu0.1~esm1
jammy

needed

noble

needed

plucky

ignored

end of life, was needs-triage
questing

released

1.15-2ubuntu0.1
upstream

released

1.17.0

Показывать по

EPSS

Процентиль: 0%
0.00005
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.

CVSS3: 5.3
debian
3 месяца назад

wlc is a Weblate command-line client using Weblate's REST API. Prior t ...

CVSS3: 5.3
github
3 месяца назад

Weblate wlc has insecure API key configuration

EPSS

Процентиль: 0%
0.00005
Низкий

5.3 Medium

CVSS3