Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2p9g-x3cv-5hh4 | Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the lookup to projects the user can access, so they return HTTP 403 (Forbidden) instead of 404 (Not Found) when a user requests an object they are not authorized to see. This difference lets unauthorized users infer whether a given object exists in a private Weblate project. The issue has been fixed in version 2026.7. | |
| Title | Observable object existence disclosure in private Weblate projects via globally scoped object lookups | |
| Weaknesses | CWE-203 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-27T13:51:40.681Z
Reserved: 2026-06-16T16:16:32.628Z
Link: CVE-2026-55227
Updated: 2026-08-27T13:51:37.879Z
Status : Received
Published: 2026-08-26T21:16:38.587
Modified: 2026-08-27T17:18:48.580
Link: CVE-2026-55227
No data.
OpenCVE Enrichment
Updated: 2026-08-26T23:00:14Z
Github GHSA