id: PYSEC-2026-3416 published: "2026-07-13T15:46:29.565097Z" modified: "2026-07-13T16:07:30.918681Z" aliases: - CVE-2026-50127 - GHSA-vmfc-9982-2m45 summary: "Weblate SSRF: outbound URL guard misses some private ranges" details: "### Impact\n\nWeblate's `VCS_RESTRICT_PRIVATE` did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions.\n\n### Patches\n\n* https://github.com/WeblateOrg/weblate/pull/19768\n\n### Resources\n\nThe issue was reported by @tonghuaroot via GitHub, and the same user also provided the initial patch." affected: - package: name: weblate ecosystem: PyPI purl: pkg:pypi/weblate ranges: - type: ECOSYSTEM events: - introduced: "5.15" - fixed: "2026.6" versions: - "2026.5" - "5.15" - 5.15.1 - 5.15.2 - "5.16" - 5.16.1 - 5.16.2 - "5.17" - 5.17.1 references: - type: WEB url: https://github.com/WeblateOrg/weblate/security/advisories/GHSA-vmfc-9982-2m45 - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2026-50127 - type: WEB url: https://github.com/WeblateOrg/weblate/pull/19768 - type: PACKAGE url: https://github.com/WeblateOrg/weblate - type: WEB url: https://github.com/WeblateOrg/weblate/releases/tag/weblate-2026.6 - type: PACKAGE url: https://pypi.org/project/weblate - type: ADVISORY url: https://github.com/advisories/GHSA-vmfc-9982-2m45 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N