Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
Moderate severity
GitHub Reviewed
Published
Apr 15, 2026
in
WeblateOrg/weblate
•
Updated Apr 16, 2026
Description
Published by the National Vulnerability Database
Apr 15, 2026
Published to the GitHub Advisory Database
Apr 16, 2026
Reviewed
Apr 16, 2026
Last updated
Apr 16, 2026
Impact
The ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects.
Patches
References
This issue was reported by @spbavarva via GitHub.
References