Weblate 是一个基于 Web 的持续本地化平台,用于管理软件翻译。在 2026.7 版本之前的版本中,具有内置“编辑源”角色的用户可以存储一个恶意的正则表达式于源字符串的标志(flags)中,该正则表达式在执行时没有任何超时限制,从而允许攻击者通过停滞请求来造成服务拒绝(Denial of Service)。通过 质量检查和正则表达式占位符提供的正则表达式,虽然在验证期间会被编译,但随后会在 和 中针对翻译内容运行,且没有时间限制,因此像 这样的灾难性回溯模式可能会无限期地消耗 CPU。由于当源单元的标志发生
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WeblateOrg | weblate | < 2026.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55228 | 8.1 HIGH | Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorize |
| CVE-2026-61792 | 7.7 HIGH | Weblate path traversal allows a project administrator to read arbitrary files via App stor |
| CVE-2026-77507 | 5.3 MEDIUM | Weblate: Object-scoped RSS feeds disclose private change history to unauthorized users |
| CVE-2026-61790 | 4.4 MEDIUM | Weblate: Team-enforced 2FA is bypassed for global permissions |
| CVE-2026-62249 | 4.3 MEDIUM | Weblate: Restricted-component change history leaked to non-member project users through th |
| CVE-2026-55227 | 4.3 MEDIUM | Observable object existence disclosure in private Weblate projects via globally scoped obj |
| CVE-2026-77508 | 3.5 LOW | Weblate: Unverified REST API email changes |
| CVE-2026-77573 | 3.5 LOW | Weblate: DNS rebinding in VCS operations allows server-side request forgery |
No comments yet