Weblate Localization Tool Vulnerability in Version 5.15 to Prior to 2026.6
CVE-2026-50127

5.9MEDIUM

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-50127?

Weblate, a web-based localization tool, has a vulnerability in its version control system settings. From version 5.15 up until before version 2026.6, the VCS_RESTRICT_PRIVATE feature did not effectively validate certain transitional IPv6 ranges, multicast addresses, and semi-private IPv4 ranges. This flaw allowed specific addresses to bypass intended private range restrictions. It was crucial that users upgrade to version 2026.6, where this issue has been addressed and resolved.

Affected Version(s)

weblate >= 5.15, < 2026.6

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.