An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS12bWZjLTk5ODItMm00Nc4ABaUn

Moderate CVSS: 5.9 EPSS: 0.00291% (0.206 Percentile) EPSS:

Weblate SSRF: outbound URL guard misses some private ranges

Affected Packages Affected Versions Fixed Versions
pypi:weblate
PURL: pkg:pypi/weblate
>= 5.15, < 2026.6 2026.6
0 Dependent packages
2 Dependent repositories
213,240 Downloads last month

Affected Version Ranges

All affected versions

5.15.1, 5.15.2, 5.16.1, 5.16.2, 5.17.1

All unaffected versions

2.10.1, 2.13.1, 2.14.1, 2.17.1, 2.19.1, 3.0.1, 3.1.1, 3.2.1, 3.2.2, 3.5.1, 3.6.1, 3.7.1, 3.9.1, 3.10.1, 3.10.2, 3.10.3, 3.11.1, 3.11.2, 3.11.3, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.1.1, 4.2.1, 4.2.2, 4.3.1, 4.3.2, 4.4.1, 4.4.2, 4.5.1, 4.5.2, 4.5.3, 4.6.1, 4.6.2, 4.7.1, 4.7.2, 4.8.1, 4.9.1, 4.10.1, 4.11.1, 4.11.2, 4.12.1, 4.12.2, 4.13.1, 4.14.1, 4.14.2, 4.15.1, 4.15.2, 4.16.1, 4.16.2, 4.16.3, 4.16.4, 4.18.1, 4.18.2, 5.0.1, 5.0.2, 5.1.1, 5.2.1, 5.3.1, 5.4.1, 5.4.2, 5.4.3, 5.5.2, 5.5.3, 5.5.4, 5.5.5, 5.6.1, 5.6.2, 5.7.1, 5.7.2, 5.8.1, 5.8.2, 5.8.3, 5.8.4, 5.9.1, 5.9.2, 5.10.1, 5.10.2, 5.10.3, 5.10.4, 5.11.1, 5.11.3, 5.11.4, 5.12.1, 5.12.2, 5.13.1, 5.13.2, 5.13.3, 5.14.1, 5.14.2, 5.14.3, 2026.6.1, 2026.7.1

Impact

Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions.

Patches

Resources

The issue was reported by @tonghuaroot via GitHub, and the same user also provided the initial patch.

References: