4.1
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Description
Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook add-on as a workaround.
Basic Information
ID
CVE-2026-39845
Source
GitHub_M
Published
Apr 15, 2026 at 18:26
Affected Product
Vendor
WeblateOrg
Product
weblate
Version
< 5.17
Affected Versions
WeblateOrg weblate < 5.17