<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T04:48:56.792008+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-34242</id>
    <title>CVE-2026-34242 — Weblate: Arbitrary File Read via Symlink</title>
    <updated>2026-10-05T04:48:56.793714+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> WeblateOrg weblate</p>
<p>Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially  following symlinks outside the repository. This issue has been fixed in version 5.17.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-34242"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hv99-mxm5-q397</id>
    <title>GHSA-hv99-mxm5-q397 — Weblate: Arbitrary File Read via Symlink</title>
    <updated>2026-10-05T04:48:56.793781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: weblate</p>
<p>### Impact</p>
<p>The ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository.</p>
<p>### Patches</p>
<p>* https://github.com/WeblateOrg/weblate/pull/18683</p>
<p>### References</p>
<p>Thanks to @DavidCarliez for reporting this vulnerability via GitHub.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hv99-mxm5-q397"/>
  </entry>
</feed>
