Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77573— Weblate: DNS rebinding in VCS operations allows server-side request forgery

Quick assessment

Affected
WeblateOrg weblate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Weblate 是一个基于 Web 的持续本地化平台,用于管理软件翻译。在 2026.8 版本之前,拥有组件仓库 URL 管理权限的用户可以通过 DNS 重绑定(DNS rebinding)漏洞,在对版本控制系统(VCS)执行操作时,对内部服务发起服务器端请求伪造(SSRF)攻击。 具体来说,Weblate 仅验证域名首次 DNS 解析的结果,但随后实际连接外部 VCS 客户端时会执行独立的 DNS 查找。因此,攻击者可以控制一个最初解析到公网地址的域名,在建立连接前将其重新指向内部或私有地址。 通过触发克隆(cl

CVSS 3.5 · Low

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77573

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Weblate: DNS rebinding in VCS operations allows server-side request forgery
Source: CVE Program / CVE List V5
Vulnerability Description
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs can perform server-side request forgery against internal services through DNS rebinding during VCS operations. Weblate validates the hostname's first DNS resolution, but the external VCS clients that later connect perform a separate DNS lookup, so an attacker-controlled hostname that initially resolves to a public address can be re-pointed to an internal or private address before the connection is made. By triggering a clone, fetch, push, or similar remote operation, the attacker can cause Weblate to reach internal VCS-compatible services and potentially expose private repository contents. Installations that permit untrusted repository hostnames while using VCS_RESTRICT_PRIVATE=True are affected. This issue is fixed in version 2026.8.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WeblateOrg weblate < 2026.8 -

II. Public POCs for CVE-2026-77573

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77573

登录查看更多情报信息。

Vendor Advisories for CVE-2026-77573 (1)

Same Patch Batch · WeblateOrg · 2026-08-26 · 9 CVEs total

CVE-2026-55228 8.1 HIGH Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorize
CVE-2026-61792 7.7 HIGH Weblate path traversal allows a project administrator to read arbitrary files via App stor
CVE-2026-62326 6.5 MEDIUM Weblate Has Uncontrolled Resource Consumption via
CVE-2026-77507 5.3 MEDIUM Weblate: Object-scoped RSS feeds disclose private change history to unauthorized users
CVE-2026-61790 4.4 MEDIUM Weblate: Team-enforced 2FA is bypassed for global permissions
CVE-2026-62249 4.3 MEDIUM Weblate: Restricted-component change history leaked to non-member project users through th
CVE-2026-55227 4.3 MEDIUM Observable object existence disclosure in private Weblate projects via globally scoped obj
CVE-2026-77508 3.5 LOW Weblate: Unverified REST API email changes

IV. Related Vulnerabilities

V. Comments for CVE-2026-77573

No comments yet


Leave a comment