CVE-2026-77573: Weblate: DNS rebinding in VCS operations allows server-side request forgery

Published Aug 26, 2026
·
Updated

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs can perform server-side request forgery against internal services through DNS rebinding during VCS operations. Weblate validates the hostname's first DNS resolution, but the external VCS clients that later connect perform a separate DNS lookup, so an attacker-controlled hostname that initially resolves to a public address can be re-pointed to an internal or private address before the connection is made. By triggering a clone, fetch, push, or similar remote operation, the attacker can cause Weblate to reach internal VCS-compatible services and potentially expose private repository contents. Installations that permit untrusted repository hostnames while using VCSRESTRICTPRIVATE=True are affected. This issue is fixed in version 2026.8.

Affected Software

1 affected component
Weblate weblate<2026.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Weblate to a version that resolves this vulnerability.

    Fixed in 2026.8
  2. Configuration

    Ensure VCS_RESTRICT_PRIVATE is set to True to restrict untrusted repository hostnames from accessing private/internal VCS endpoints during VCS operations (issue affects installations that permit untrusted repository hostnames while using VCS_RESTRICT_PRIVATE=True).

    Weblate VCS_RESTRICT_PRIVATE = True

Event History

Aug 26, 2026
CVE Published
via MITRE·08:48 PM
Data Sourced
via MITRE·08:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which installations are affected?

Installations that allow untrusted repository hostnames while VCS_RESTRICT_PRIVATE=True is enabled are affected. The issue applies to versions earlier than 2026.8.

2

What level of access does an attacker need?

The attacker needs permission to manage component repository URLs. They must control a hostname and be able to change its DNS resolution between Weblate's initial validation and the VCS client's later connection.

3

What actions can trigger the vulnerable connection?

A clone, fetch, push, or similar remote VCS operation can trigger the connection. This can cause Weblate to contact internal VCS-compatible services and may expose private repository contents.

4

How can the risk be reduced if upgrading is not immediately possible?

Do not permit untrusted users to configure repository hostnames or URLs. Restrict repository URLs to trusted hosts until version 2026.8 can be installed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203