Denial of Service Vulnerability in Weblate by Weblate
CVE-2026-62326
6.5MEDIUM
What is CVE-2026-62326?
Weblate, a web-based continuous localization platform, is susceptible to a denial of service due to improper handling of malicious regular expressions in source strings. Users with the 'Edit source' role can input hazardous regex patterns that lead to indefinite CPU consumption, causing the system to stall and potentially deny service. This is due to the lack of execution time limits when validating these patterns during translation content checks. Such vulnerabilities can be triggered by a single modification, affecting all linked units, thereby amplifying the denial of service risk. The issue has been addressed in version 2026.7.
Affected Version(s)
weblate < 2026.7
