<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:05:50.356051+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-33214</id>
    <title>CVE-2026-33214 — Weblate has improper access control for the translation memory API</title>
    <updated>2026-10-04T21:05:50.357770+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> WeblateOrg weblate</p>
<p>Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't enforce proper access control. This issue has been fixed in version 5.17. If users are unable to update immediately, they can work around this issue by blocking access to /api/memory/ in the HTTP server, which removes access to this feature.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-33214"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mpf5-3vph-q75r</id>
    <title>GHSA-mpf5-3vph-q75r — Weblate: Improper access control for the translation memory in API</title>
    <updated>2026-10-04T21:05:50.357825+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Weblate</p>
<p>### Impact
The translation memory API exposed unintended endpoints, which in turn didn't do proper access control.</p>
<p>### Patches
* https://github.com/WeblateOrg/weblate/pull/18513</p>
<p>### Workarounds
Blocking access to `/api/memory/` in the HTTP server removes access to this feature.</p>
<p>### References
This issue was reported by [ggamno](https://hackerone.com/ggamno) via HackerOne.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mpf5-3vph-q75r"/>
  </entry>
</feed>
