CVE-2026-33440
MEDIUM
NVD
CVSS Score
5
Severity
MEDIUM
Published
Apr 15, 2026
Vendor
unknown
Description
Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. This issue has been fixed in version 5.17.