Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-62326— Weblate Has Uncontrolled Resource Consumption via

Quick assessment

Affected
WeblateOrg weblate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Weblate 是一个基于 Web 的持续本地化平台,用于管理软件翻译。在 2026.7 版本之前的版本中,具有内置“编辑源”角色的用户可以存储一个恶意的正则表达式于源字符串的标志(flags)中,该正则表达式在执行时没有任何超时限制,从而允许攻击者通过停滞请求来造成服务拒绝(Denial of Service)。通过 质量检查和正则表达式占位符提供的正则表达式,虽然在验证期间会被编译,但随后会在 和 中针对翻译内容运行,且没有时间限制,因此像 这样的灾难性回溯模式可能会无限期地消耗 CPU。由于当源单元的标志发生

CVSS 6.5 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-62326

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Weblate Has Uncontrolled Resource Consumption via
Source: CVE Program / CVE List V5
Vulnerability Description
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a user with the built-in "Edit source" role can store a malicious regular expression in a source string's flags that is executed without any timeout, allowing them to stall requests and deny service. Regular expressions supplied through the regex: quality check and regex placeholders are compiled during validation but later run against translation content in RegexCheck and PlaceholderCheck with no time limit, so a catastrophic-backtracking pattern like ^(a|aa)+$ can consume CPU indefinitely. Because Weblate re-runs these checks for every linked target unit in the same request when a source unit's flags change, a single edit can trigger sustained CPU-bound denial of service. This issue is fixed in version 2026.7.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WeblateOrg weblate < 2026.7 -

II. Public POCs for CVE-2026-62326

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-62326

登录查看更多情报信息。

Patches & Fixes for CVE-2026-62326 (1)

Vendor Advisories for CVE-2026-62326 (1)

Same Patch Batch · WeblateOrg · 2026-08-26 · 9 CVEs total

CVE-2026-55228 8.1 HIGH Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorize
CVE-2026-61792 7.7 HIGH Weblate path traversal allows a project administrator to read arbitrary files via App stor
CVE-2026-77507 5.3 MEDIUM Weblate: Object-scoped RSS feeds disclose private change history to unauthorized users
CVE-2026-61790 4.4 MEDIUM Weblate: Team-enforced 2FA is bypassed for global permissions
CVE-2026-62249 4.3 MEDIUM Weblate: Restricted-component change history leaked to non-member project users through th
CVE-2026-55227 4.3 MEDIUM Observable object existence disclosure in private Weblate projects via globally scoped obj
CVE-2026-77508 3.5 LOW Weblate: Unverified REST API email changes
CVE-2026-77573 3.5 LOW Weblate: DNS rebinding in VCS operations allows server-side request forgery

IV. Related Vulnerabilities

V. Comments for CVE-2026-62326

No comments yet


Leave a comment