CVE-2025-49134: Weblate exposes personal IP address via e-mail
Impact
The audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters.
Patches
This issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102.
References
Thanks to micael1 for reporting this issue at HackerOne.
Other sources
Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. This issue has been patched in version 5.12.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49134?
CVE-2025-49134 has been assessed as a medium severity vulnerability due to the exposure of user IP addresses.
How do I fix CVE-2025-49134?
To fix CVE-2025-49134, upgrade to Weblate version 5.12 or later.
What does CVE-2025-49134 impact?
CVE-2025-49134 impacts the audit log notifications by leaking full IP addresses of users.
Who is affected by CVE-2025-49134?
Users of Weblate versions prior to 5.12 are affected by CVE-2025-49134.
What is the nature of the risk associated with CVE-2025-49134?
The risk associated with CVE-2025-49134 is that third-party servers can capture user IP addresses, potentially compromising user privacy.