5.9 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
6 packages
- python313Packages.weblate-fonts
- python314Packages.weblate-fonts
- python313Packages.weblate-schemas
- python314Packages.weblate-schemas
- python313Packages.weblate-language-data
- python314Packages.weblate-language-data
- @LeSuisse accepted
- @LeSuisse published on GitHub
Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)
Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions. This issue has been patched in version 2026.6.
References
-
https://github.com/WeblateOrg/weblate/security/advisories/GHSA-vmfc-9982-2m45 x_refsource_CONFIRM
-
https://github.com/WeblateOrg/weblate/pull/19768 x_refsource_MISC
-
https://github.com/WeblateOrg/weblate/releases/tag/weblate-2026.6 x_refsource_MISC
Affected products
- ==>= 5.15, < 2026.6
Matching in nixpkgs
Ignored packages (6)
pkgs.python313Packages.weblate-fonts
Weblate fonts collection
pkgs.python314Packages.weblate-fonts
Weblate fonts collection
pkgs.python313Packages.weblate-schemas
Schemas used by Weblate
pkgs.python314Packages.weblate-schemas
Schemas used by Weblate
pkgs.python313Packages.weblate-language-data
Language definitions used by Weblate
Package maintainers
-
@erictapen Kerstin Humm <kerstin@erictapen.name>
4.6 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
6 packages
- python313Packages.weblate-fonts
- python314Packages.weblate-fonts
- python313Packages.weblate-schemas
- python314Packages.weblate-schemas
- python313Packages.weblate-language-data
- python314Packages.weblate-language-data
- @LeSuisse accepted
- @LeSuisse published on GitHub
Weblate: Stored HTML injection in editor search preview
Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and context as HTML without escaping. Any contributor whose content reaches those fields stores HTML and CSS that runs inside the authenticated editor of every user who runs a matching search. This issue has been patched in version 2026.5.
References
-
https://github.com/WeblateOrg/weblate/security/advisories/GHSA-6wxc-8mgq-w26m x_refsource_CONFIRM
-
https://github.com/WeblateOrg/weblate/pull/19422 x_refsource_MISC
-
https://github.com/WeblateOrg/weblate/releases/tag/weblate-2026.5 x_refsource_MISC
Affected products
- ==< 2026.5
Matching in nixpkgs
Ignored packages (6)
pkgs.python313Packages.weblate-fonts
Weblate fonts collection
pkgs.python314Packages.weblate-fonts
Weblate fonts collection
pkgs.python313Packages.weblate-schemas
Schemas used by Weblate
pkgs.python314Packages.weblate-schemas
Schemas used by Weblate
pkgs.python313Packages.weblate-language-data
Language definitions used by Weblate
Package maintainers
-
@erictapen Kerstin Humm <kerstin@erictapen.name>