Weblate Localization Tool Vulnerability in Prior Versions
CVE-2026-33440
5MEDIUM
What is CVE-2026-33440?
Weblate, an open-source web-based localization tool, has a vulnerability that affects how the ALLOWED_ASSET_DOMAINS setting is applied in versions prior to 5.17. This flaw allows possible redirects due to insufficient restrictions on these settings, which could lead to security risks during user interactions. The issue has been addressed with a fix in Weblate version 5.17.
Affected Version(s)
weblate < 5.17
