Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions. This issue has been patched in version 2026.6.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions. This issue has been patched in version 2026.6. | |
| Title | Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96) | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-10T19:56:37.829Z
Reserved: 2026-06-03T18:49:32.275Z
Link: CVE-2026-50127
No data.
Status : Deferred
Published: 2026-06-10T20:17:29.427
Modified: 2026-06-10T20:21:20.207
Link: CVE-2026-50127
No data.
OpenCVE Enrichment
Updated: 2026-06-10T21:30:36Z