Vulnerability Description
Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook add-on as a workaround.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Weblate | Weblate | < 5.17 |
Related Weaknesses (CWE)
References
- https://github.com/WeblateOrg/weblate/pull/18815Issue TrackingPatch
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-f8hv-g549-hwg2Third Party Advisory
FAQ
What is CVE-2026-39845?
CVE-2026-39845 is a vulnerability with a CVSS score of 4.1 (MEDIUM). Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable t...
How severe is CVE-2026-39845?
CVE-2026-39845 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-39845?
Check the references section above for vendor advisories and patch information. Affected products include: Weblate Weblate.