Weblate: SSRF via the webhook add-on using unprotected fetch_url()
Moderate severity
GitHub Reviewed
Published
Apr 15, 2026
in
WeblateOrg/weblate
•
Updated Apr 16, 2026
Description
Published by the National Vulnerability Database
Apr 15, 2026
Published to the GitHub Advisory Database
Apr 16, 2026
Reviewed
Apr 16, 2026
Last updated
Apr 16, 2026
Impact
The webhook add-on did not utilize existing SSRF protection.
Patches
Workarounds
Disabling the add-on would avoid misusing this.
References
Thanks to @Lihfdgjr for reporting this via GitHub.
References