Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)
CVE-2026-50127

5.9MEDIUM

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-50127?

Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions. This issue has been patched in version 2026.6.

Affected Version(s)

weblate >= 5.15, < 2026.6

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.