id: PYSEC-2026-2311 published: "2026-04-15T18:17:19.897Z" modified: "2026-07-13T05:52:33.580264Z" aliases: - CVE-2026-33212 - GHSA-vj45-x3pj-f4w4 details: Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. The attacker needs to brute-force the random UUID of the task, so exploiting this is unlikely with the default API rate limits. This issue has been fixed in version 5.17. affected: - package: name: weblate ecosystem: PyPI purl: pkg:pypi/weblate ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: "5.17" versions: - "1.9" - "2.0" - "2.1" - "2.10" - 2.10.1 - "2.11" - "2.12" - "2.13" - 2.13.1 - "2.14" - 2.14.1 - "2.15" - "2.16" - "2.17" - 2.17.1 - "2.18" - "2.19" - 2.19.1 - "2.2" - "2.20" - "2.3" - "2.4" - "2.5" - "2.6" - "2.7" - "2.8" - "2.9" - "3.0" - 3.0.1 - "3.1" - 3.1.1 - "3.10" - 3.10.1 - 3.10.2 - 3.10.3 - "3.11" - 3.11.1 - 3.11.2 - 3.11.3 - "3.2" - 3.2.1 - 3.2.2 - "3.3" - "3.4" - "3.5" - 3.5.1 - "3.6" - 3.6.1 - "3.7" - 3.7.1 - "3.8" - "3.9" - 3.9.1 - "4.0" - 4.0.1 - 4.0.2 - 4.0.3 - 4.0.4 - "4.1" - 4.1.1 - "4.10" - 4.10.1 - "4.11" - 4.11.1 - 4.11.2 - "4.12" - 4.12.1 - 4.12.2 - "4.13" - 4.13.1 - "4.14" - 4.14.1 - 4.14.2 - "4.15" - 4.15.1 - 4.15.2 - "4.16" - 4.16.1 - 4.16.2 - 4.16.3 - 4.16.4 - "4.17" - "4.18" - 4.18.1 - 4.18.2 - "4.2" - 4.2.1 - 4.2.2 - "4.3" - 4.3.1 - 4.3.2 - "4.4" - 4.4.1 - 4.4.2 - "4.5" - 4.5.1 - 4.5.2 - 4.5.3 - "4.6" - 4.6.1 - 4.6.2 - "4.7" - 4.7.1 - 4.7.2 - "4.8" - 4.8.1 - "4.9" - 4.9.1 - "5.0" - 5.0.1 - 5.0.2 - "5.1" - 5.1.1 - "5.10" - 5.10.1 - 5.10.2 - 5.10.3 - 5.10.4 - "5.11" - 5.11.1 - 5.11.3 - 5.11.4 - 5.12.1 - 5.12.2 - "5.13" - 5.13.1 - 5.13.2 - 5.13.3 - "5.14" - 5.14.1 - 5.14.2 - 5.14.3 - "5.15" - 5.15.1 - 5.15.2 - "5.16" - 5.16.1 - 5.16.2 - "5.2" - 5.2.1 - "5.3" - 5.3.1 - "5.4" - 5.4.1 - 5.4.2 - 5.4.3 - "5.5" - 5.5.2 - 5.5.3 - 5.5.4 - 5.5.5 - "5.6" - 5.6.1 - 5.6.2 - "5.7" - 5.7.1 - 5.7.2 - 5.8.1 - 5.8.2 - 5.8.3 - 5.8.4 - 5.9.1 - 5.9.2 ecosystem_specific: {} references: - type: FIX url: https://github.com/WeblateOrg/weblate/commit/4e06b12cd05d087db68384e09d5f70fe883f2b70 - type: FIX url: https://github.com/WeblateOrg/weblate/security/advisories/GHSA-vj45-x3pj-f4w4 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N