CVE-2026-22250

LOW2.5EPSS 0.01%

Weblate command-line client susceptible to SSL verification skip

Published: 1/12/2026Modified: 4/28/2026

Description

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1LOW2.5CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N

References (6)