Weblate Localization Tool Vulnerability in Version 5.15 to Prior to 2026.6
CVE-2026-50127
5.9MEDIUM
What is CVE-2026-50127?
Weblate, a web-based localization tool, has a vulnerability in its version control system settings. From version 5.15 up until before version 2026.6, the VCS_RESTRICT_PRIVATE feature did not effectively validate certain transitional IPv6 ranges, multicast addresses, and semi-private IPv4 ranges. This flaw allowed specific addresses to bypass intended private range restrictions. It was crucial that users upgrade to version 2026.6, where this issue has been addressed and resolved.
Affected Version(s)
weblate >= 5.15, < 2026.6
