Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-55227

21 день назад

Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the lookup to projects the user can access, so they return HTTP 403 (Forbidden) instead of 404 (Not Found) when a user requests an object they are not authorized to see. This difference lets unauthorized users infer whether a given object exists in a private Weblate project. The issue has been fixed in version 2026.7.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2026-55227

21 день назад

Weblate is a web-based localization tool. In versions prior to 2026.7, ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2p9g-x3cv-5hh4

19 дней назад

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-55227

Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the lookup to projects the user can access, so they return HTTP 403 (Forbidden) instead of 404 (Not Found) when a user requests an object they are not authorized to see. This difference lets unauthorized users infer whether a given object exists in a private Weblate project. The issue has been fixed in version 2026.7.

CVSS3: 4.3
0%
Низкий
21 день назад
debian логотип
CVE-2026-55227

Weblate is a web-based localization tool. In versions prior to 2026.7, ...

CVSS3: 4.3
0%
Низкий
21 день назад
github логотип
GHSA-2p9g-x3cv-5hh4

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

CVSS3: 4.3
0%
Низкий
19 дней назад

Уязвимостей на страницу