CVE-2026-50127 Details
Description
Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions. This issue has been patched in version 2026.6.
A vulnerability in Weblate's outbound URL validation allowed certain addresses to bypass private range restrictions, creating a server-side request forgery (SSRF) risk. This issue affected Weblate versions 5.15 prior to 2026.6. The vulnerability arose because the VCS_RESTRICT_PRIVATE setting did not adequately consider some transitional IPv6 ranges, multicast addresses, or certain semi-private IPv4 ranges.
Users can upgrade to Weblate version 2026.6 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 10, 2026CISA-ADP
Assessed Jun 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/WeblateOrg/weblate/pull/19768 | [email protected] | Source CodeVendor |
| https://github.com/WeblateOrg/weblate/releases/tag/weblate-2026.6 | [email protected] | Release NotesVendor |
| https://github.com/WeblateOrg/weblate/security/advisories/GHSA-vmfc-9982-2m45 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Weblate | >= 5.15, < 2026.6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2026 | New CVE Received | [email protected] |
Volerion