<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:09:03.641236+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-33220</id>
    <title>CVE-2026-33220 — Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository</title>
    <updated>2026-10-04T21:09:03.642907+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> WeblateOrg weblate</p>
<p>Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper access control. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable this feature as the CDN add-on is not enabled by default.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-33220"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mqph-7h49-hqfm</id>
    <title>GHSA-mqph-7h49-hqfm — Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository</title>
    <updated>2026-10-04T21:09:03.642960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Weblate</p>
<p>### Impact
The translation memory API exposed unintended endpoints, which in turn didn't do proper access control.</p>
<p>### Patches
* https://github.com/WeblateOrg/weblate/pull/18516</p>
<p>### Workarounds
The CDN add-on is not enabled by default.</p>
<p>### References
Thanks to @spbavarva for reporting this responsibly via GitHub.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mqph-7h49-hqfm"/>
  </entry>
</feed>
